Security & Trust

Your data, protected

How we secure your data, protect your privacy, and maintain the trust of NYC's top brokerages and attorneys.

Encryption

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Database backups are encrypted and stored in geographically redundant locations.

Authentication & Access

JWT-based authentication with secure httpOnly cookies. Role-based access control ensures users only see data they're authorized to access. OAuth 2.0 support for Google SSO.

Infrastructure

Hosted on Railway with isolated production environments. PostgreSQL databases with automated daily backups, point-in-time recovery, and failover support.

Monitoring & Logging

Structured application logging with audit trails for sensitive operations. Real-time error tracking and alerting. No sensitive data in log output.

Data Privacy

We process only publicly available real estate records (ACRIS, DOF, HPD, DOB) and authorized MLS data. Personal client data is never shared or sold. See our Privacy Policy for full details.

AI & Model Security

AI valuations and market intelligence run on isolated model servers. No client data is used to train models. All AI outputs include confidence indicators and data provenance.

Questions about security?

Reach out to our team at security@tortus.io