Security at REALM
Real estate transactions run on trust. Here is how we protect what you store with us.
REALM holds transaction documents, client communications, and compliance records for licensed real estate professionals. That responsibility shapes how the platform is built: the protections below are part of the architecture, not settings someone has to remember to turn on. Each one maps to a numbered claim in our internal verification runbook, which carries the exact command that proves it against our live infrastructure, and the Vault re-verifies itself every day automatically.
Encryption everywhere
- In transit: all traffic between your browser or phone and REALM is encrypted with TLS (HTTPS).
- At rest, documents: every uploaded document is stored with AES-256 server-side encryption.
- At rest, database: the platform database is encrypted at rest with managed keys.
- Vault records: vaulted compliance records are encrypted with a dedicated key held in a hardware-backed key management service.
The REALM Vault is immutable
When a transaction file is sealed into the Vault, the stored objects are written in a write-once compliance mode: they cannot be altered or deleted by anyone, including REALM, until their retention period ends. Legal holds can pin a record beyond its retention period when circumstances require it.
The Vault also re-verifies itself: an automated daily job re-checks every sealed record's integrity (its checksum, its lock, and its retention) and raises an alert if anything does not prove out.
Audit trails that cannot be rewritten
Compliance-relevant activity (document access and changes, status transitions, review decisions) is recorded in append-only audit trails. Corrections create new entries; history is never edited or deleted. When a broker or regulator asks what happened and when, the answer is deterministic.
A resilient, recoverable database
The platform database runs on managed, encrypted infrastructure with a synchronized standby in a separate availability zone (automatic failover), continuous backups with point-in-time recovery, and deletion protection.
Access is scoped and short-lived
- Nothing REALM stores is publicly readable; storage is private by policy, at the account level.
- Document download links are signed and expire automatically after 30 days; there are no permanent public URLs to your files, and an expired link can be reissued.
- Every request is authorized against your workspace and role: a user in one brokerage can never read another's data, and platform-level access by our own team is audit-logged.
Questions or reports
If you have a security question, or believe you have found a vulnerability, contact us and we will respond promptly: