Security at AutoTC

Real estate transactions involve sensitive personal and financial data. We built AutoTC with security at every layer so you can trust us with your most important deals.

Infrastructure Security

  • Hosted on enterprise-grade cloud infrastructure with a global edge network
  • Managed PostgreSQL database with encryption at rest
  • All data encrypted in transit
  • All data encrypted at rest
  • Automatic backups and disaster recovery

Application Security

  • Row Level Security and tenant-scoped authorization help isolate each account's transaction data, documents, and communications
  • Authentication with secure, industry-standard password hashing
  • Authentication, authorization, rate limits, and abuse controls applied according to endpoint risk
  • Webhook authentication or provider-supported signature verification applied to inbound integrations
  • Validation and authorization controls around sensitive actions and data changes
  • Logging controls are designed to redact secrets and unnecessary personal data; approved processors receive data only when needed for a requested feature

Data Privacy

  • Privacy controls designed to support CCPA and other applicable privacy obligations
  • We never sell your data to third parties
  • PII handled per CCPA guidelines with strict access controls
  • User-controlled document retention with limited legal, security, billing, dispute, and legal-hold exceptions
  • Approved AI processors handle data for requested features; API customer data is not used for model training by default, though limited security logs may apply
  • Account-scoped controls limit access to transaction data. Data may be shared with authorized team users, recipients you direct, connected integrations, approved processors, and authorized support or quality personnel as described in the Privacy Policy. We seek to exclude personal information and document content before reusing form-layout patterns; linkable metadata remains protected under the Privacy Policy.

Communication Security

  • SMS sent from registered numbers with consent, opt-out, and quiet-hour controls
  • Email workflows include unsubscribe controls and standard email authentication
  • STOP and preference controls are available for SMS and for marketing or nonessential automated communications where applicable
  • Quiet-hour controls are applied to automated SMS using available recipient and jurisdiction information; users remain responsible for lawful timing

Compliance

  • Transaction files remain available while an account is open and are not removed merely because the account is inactive or suspended
  • Audit records for material AI actions and transaction changes
  • License verification uses available issuing-authority records; production availability still rolls out state by state
  • Messaging workflows support consent records, STOP/HELP handling, unsubscribe controls, and quiet hours

Responsible AI

  • AI responses are held for your review when confidence is low
  • Risky content such as legal advice or contract changes requires agent approval before sending
  • All AI interactions logged with full audit trail
  • Human-in-the-loop safeguards for sensitive operations

Report a Vulnerability

Found a security issue? We take every report seriously. Please contact our security team and we will review it promptly.

support@autotc.ai