Trust

Security at Escrobro

Real estate transactions carry financial and personal data. Security isn't a feature tier — it's the foundation.

Per-deal isolation

Every transaction is a separate workspace. Row-level security policies ensure participants access only deals they've been invited to — enforced at the database, not just the UI.

Passwordless authentication

Magic links are time-limited and single-use. No shared credentials, no client passwords stored in browser autofill for buyers who close once a decade.

Encryption

TLS 1.2+ for data in transit. Documents and database contents encrypted at rest via our cloud infrastructure providers.

Document storage

Files upload directly to encrypted object storage. Access is mediated by signed URLs — documents are not publicly enumerable or searchable.

Infrastructure

Hosted on managed cloud infrastructure with automatic patching, DDoS protection, and geographic redundancy. Production and staging environments are isolated.

Access management

Production access is limited to essential personnel on a least-privilege basis. Administrative actions are logged.

Subprocessors

We use a minimal set of infrastructure providers. Each processes data under contractual data protection terms.

ProviderPurpose
SupabaseDatabase, authentication, and file storage
VercelApplication hosting and edge delivery

Reporting vulnerabilities

If you discover a security issue, please report it to security@escrobro.com. Include a description, steps to reproduce, and impact assessment. We acknowledge reports within two business days and work with researchers under responsible disclosure. We do not pursue legal action against good-faith security research.

Compliance

Escrobro is in public preview. SOC 2 Type II and additional compliance certifications are on our roadmap for Enterprise customers. Contact sales@escrobro.com for security questionnaires and vendor review packets.

For how we handle personal data, see our Privacy Policy.