Security & trust

    Your client data, properly protected

    A real estate CRM holds the most sensitive information an agency has — buyer finances, vendor instructions, signed agreements and your entire contact database. Here is precisely how that is protected, and what we do not claim.

    Workspace isolation

    Every company's data lives in its own tenant scope. Records, files, listings and conversations are bound to the workspace that created them, and that boundary is enforced at the data-access layer rather than in the interface, so it cannot be bypassed by crafting a request.

    Role-based access control

    Permissions are granular and role-driven. The plan ships four template roles — Owner, Company Manager, Real Estate Agent, and Support — and you can define your own. Billing, subscription and company settings are separable from day-to-day CRM access, so a manager can run the business without being able to change the plan.

    Encrypted in transit

    All traffic to the platform and to the public property websites runs over TLS. Sessions are cookie-based with CSRF protection, and API access uses scoped keys that can be rotated or revoked per integration without disturbing the rest of your setup.

    Infrastructure

    The application runs behind Cloudflare, with bot protection on public forms and registration. Media and documents are stored per company with access mediated by the same permission model as the records they belong to — a file is never reachable by URL alone from outside your workspace.

    Audit trail and recovery

    Activity is logged against records so you can see who changed what and when, and recover from mistakes. E-signature envelopes handled through the managed provider carry a completion audit certificate alongside the signed deliverable.

    Data ownership and portability

    Your data is yours. Exports are available from the modules you use rather than gated behind a plan upgrade, and account deletion removes workspace data on a defined schedule rather than retaining it indefinitely.

    Privacy and cross-border data

    RealEstateCRM.io serves agencies across Europe, the Middle East, Asia and the Americas, which means personal data routinely moves between jurisdictions. At registration we ask you to acknowledge cross-border processing explicitly rather than burying it in the terms, and marketing consent is collected separately from the service agreement so the two are never conflated.

    You remain the data controller for the contacts in your workspace. We process that data to provide the service you have subscribed to. Your CRM data is not used to train AI models — AI features operate within your workspace and answer your own prompts only.

    Full detail is in our privacy policy and terms of service.

    Reporting a vulnerability

    If you believe you have found a security issue, please contact us directly rather than disclosing it publicly. We will acknowledge your report and keep you informed while we investigate.

    Contact our team