Security & Trust
How we secure your data, protect your privacy, and maintain the trust of NYC's top brokerages and attorneys.
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Database backups are encrypted and stored in geographically redundant locations.
JWT-based authentication with secure httpOnly cookies. Role-based access control ensures users only see data they're authorized to access. OAuth 2.0 support for Google SSO.
Hosted on Railway with isolated production environments. PostgreSQL databases with automated daily backups, point-in-time recovery, and failover support.
Structured application logging with audit trails for sensitive operations. Real-time error tracking and alerting. No sensitive data in log output.
We process only publicly available real estate records (ACRIS, DOF, HPD, DOB) and authorized MLS data. Personal client data is never shared or sold. See our Privacy Policy for full details.
AI valuations and market intelligence run on isolated model servers. No client data is used to train models. All AI outputs include confidence indicators and data provenance.
Reach out to our team at security@tortus.io