The product includes practical safeguards for authentication, tenant isolation, integrations, and messaging. Your hosting and provider configuration remain part of the security boundary.
Production deployments should terminate HTTPS at a trusted proxy or hosting platform.
API access is scoped by tenant and protected with server-side authorization checks.
Twilio webhook signatures are validated before inbound messages are processed.
Owner, admin, transaction-coordinator, agent, and read-only roles limit sensitive actions.
Integration credentials are stored encrypted and are not exposed through application responses.
Authentication and public intake endpoints include request validation and rate limits.
Production operators should use managed PostgreSQL, HTTPS, restricted network access, backups, and monitoring appropriate to their risk profile. These controls are deployment responsibilities.
Tenant identifiers are enforced in service queries, integration secrets are encrypted before storage, and sensitive values are excluded from normal API responses and logs.
The application uses signed, revocable sessions in HttpOnly cookies, verified email accounts, strong password requirements, and server-side role checks. MFA and SSO are not currently included.
RealtyTechAI does not currently claim a third-party security certification. Customers are responsible for assessing their own legal, privacy, retention, consent, and messaging obligations.
Operators should configure logs, alerts, backups, key rotation, and an incident-response process before handling production data.
If you discover a security issue, use the contact page and avoid including live credentials or customer data in the initial report.