Trust
Security at Escrobro
Real estate transactions carry financial and personal data. Security isn't a feature tier — it's the foundation.
Per-deal isolation
Every transaction is a separate workspace. Row-level security policies ensure participants access only deals they've been invited to — enforced at the database, not just the UI.
Passwordless authentication
Magic links are time-limited and single-use. No shared credentials, no client passwords stored in browser autofill for buyers who close once a decade.
Encryption
TLS 1.2+ for data in transit. Documents and database contents encrypted at rest via our cloud infrastructure providers.
Document storage
Files upload directly to encrypted object storage. Access is mediated by signed URLs — documents are not publicly enumerable or searchable.
Infrastructure
Hosted on managed cloud infrastructure with automatic patching, DDoS protection, and geographic redundancy. Production and staging environments are isolated.
Access management
Production access is limited to essential personnel on a least-privilege basis. Administrative actions are logged.
Subprocessors
We use a minimal set of infrastructure providers. Each processes data under contractual data protection terms.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, and file storage | United States |
| Vercel | Application hosting and edge delivery | United States |
Reporting vulnerabilities
If you discover a security issue, please report it to security@escrobro.com. Include a description, steps to reproduce, and impact assessment. We acknowledge reports within two business days and work with researchers under responsible disclosure. We do not pursue legal action against good-faith security research.
Compliance
Escrobro is in public preview. SOC 2 Type II and additional compliance certifications are on our roadmap for Enterprise customers. Contact sales@escrobro.com for security questionnaires and vendor review packets.
For how we handle personal data, see our Privacy Policy.