You're trusting us with your properties, your numbers and your plans. Here's how that data is protected — in plain terms, and in principle. If you're the kind of person who reads these pages properly, this one's for you.
Access is enforced at the database layer with row-level security — every request is scoped to your account by the database itself, not just by application code. One member's queries can never reach another member's data, even in the event of an application bug.
Everything moving between you and us travels over TLS. Everything stored is encrypted at rest with AES-256. Your portfolio is never sitting in plain text, on the wire or on disk.
Authentication is handled by a dedicated, industry-standard identity layer — not something we built ourselves. Passwords are salted and hashed (we never store or even see your password), and sessions use short-lived, revocable tokens.
All payments are processed by Stripe, a PCI DSS Level 1 provider — the highest tier of payment-security certification. Your credit card details go straight to Stripe and never land on our servers.
Our platform runs on cloud infrastructure that independently maintains SOC 2 Type II and ISO 27001 certification, with security patching managed at the provider level. We don't run our own servers in a cupboard.
Only the few team members who genuinely need access to production systems have it, that access is scoped to what their role requires, and it's logged. There's no open door to member data internally.
Your data is backed up automatically, so it can be restored if anything ever goes wrong. Resilience isn't an afterthought — it's part of how the platform is run day to day.
We never sell your data, and nothing is shared with the community or Deal Room unless you choose to put it there. You can ask for a copy of your data, or ask us to delete it, at any time.
Last reviewed: July 2026.