Security & data
Where your data lives, and who can see it.
- Region
- United States (US East)
- Isolation
- Row-level security
- Backups
- Daily
- Certification
- None yet
§ 01Infrastructure
How it's run.
- Application hosting
- Railway.
- Database
- Supabase Postgres, hosted in the United States (US East).
- Separation
- Row-level security on every table keeps each organization's records apart.
- Accounts
- Invite-only. Nobody can create an account from the sign-in page.
- Permissions
- Role-based: brokers and admins see the firm; agents see their own book.
- Audit log
- Changes to records, and what was sent, are logged.
- In transit
- HTTPS only, with HSTS, a content security policy and standard security headers.
- Backups
- The database is backed up daily.
- Monitoring
- Health checks and error monitoring on the production application.
§ 02Controls in the product
Rules the system enforces.
No listing goes public without a recorded listing agreement.
Upload the signed agreement and the system reads the signers and dates for a broker to confirm. Until then, the listing stays off the public pages.
No comp reaches a client document without its source.
Every comp price in a flyer or OM has to name where it came from — a document or an attested import. A price that can't doesn't print.
Nothing the assistant writes reaches a client on its own.
Anything meant for someone outside the firm comes back as a draft or a proposal. A person approves, edits or rejects it — and approving an email draft doesn't send it.
Agents see their book. Brokers see the firm.
Enforced by row-level security in the database, not just hidden on screen: an agent sees the records they own, collaborate on or are party to; broker admins see everything.
Changes leave a trail.
An audit log records changes to records and what was sent.
§ 03Your data
Your book stays yours.
- Ownership
- Your brokerage's records belong to your brokerage.
- Export
- Full export on request while you're a customer and for 30 days after you leave. Then we delete it and confirm the deletion in writing.
- Our access
- Your order form sets out when our team may access your account to support you.
§ 04Not yet
What we haven't done.
- Certifications
- TAP CRM has not completed a third-party security certification such as SOC 2 or ISO 27001.
- Penetration test
- No third-party penetration test report is available.
Questions about how your data is handled? Ask us. Our privacy policy covers personal information.