Security & privacy
Client Rooms hold sensitive things: financial documents, family decisions, and details of the largest purchase most people ever make. Here is concretely what we do to protect them: no vague assurances and no badges we haven’t earned.
Each agent’s workspace is isolated at the database rule layer. One agent’s buyers, properties, and documents are never queryable from another agent’s account. Access rules enforce isolation, not application code alone.
Buyer documents are never publicly addressable. Access happens through short-lived signed links that expire automatically. There is no “anyone with the link” mode.
Each view and download of a vault document is written to an audit log: who, what, and when. Agents and buyers can see the trail for their own files.
Buyer invitations use long, random, single-purpose tokens, not predictable URLs. Agents can revoke a buyer’s link at any time, immediately cutting off room access.
You can export your data and delete your account from settings without filing a ticket. Deletion removes content from production systems; backup copies age out on a fixed schedule.
AI features process your content to produce recaps and property cards. We do not use documents, recordings, or buyer data to train AI models, and our provider agreements reflect that.
OfferReady runs on Google Cloud and Firebase infrastructure. Data is encrypted in transit (TLS) and at rest using managed platform encryption.
We don’t list compliance certifications we haven’t completed, and we won’t add a badge before an independent auditor signs off. What you read above is our actual posture today. We’ll publish formal audits here when complete.
Found a vulnerability, or have a question about how we handle data? Email albert@arbicgroup.com. Security reports go to the top of the queue.
For details about what we collect and how it’s used, read the Privacy Policy.