Security & Data Practices

How we protect your data.

Real estate is a regulated business. Security, privacy, and compliance are the foundation, not an extra.

Infrastructure

Hosted on Vercel's enterprise edge network with 99.99% uptime SLA. All traffic encrypted with TLS 1.3. Application deployed across multiple availability zones with automatic failover. Database hosted on Supabase with daily automated backups and point-in-time recovery.

Data Storage

User and transaction data stored in Supabase PostgreSQL with row-level security. All data encrypted at rest using AES-256 encryption. Database connections secured via connection pooling with SSL enforcement. No data is stored in plaintext.

MLS Data Handling

Optional /search and listing URLs are not part of the $99 CRM. Until a licensed MLS feed is connected they show Treasure Valley sample inventory, not live Intermountain MLS. If a licensed feed is later connected, listings sync into a search replica used only for those pages. We do not sell listing data and we do not claim live MLS until a licensed feed is connected.

Access Controls

Role-based access control with tenant isolation. Each agent's data is stored within their own tenant boundary. No cross-tenant data access is possible at the application or database level. Administrative access is restricted and logged.

Document Security

Client documents stored in Supabase Storage with bucket-level access policies. All document access is via signed URLs with 15-minute expiry. No permanent public URLs are generated for sensitive documents. File uploads restricted by type and size.

Authentication

Agent, lender, and client-portal sign-in use Google OAuth 2.0 or email and password. Agents authenticate through Supabase Auth. Lender and client portals set httpOnly session cookies (30 days) after Google or password. Password-reset emails only set a password — daily login is never an emailed link.

Compliance

RESPA co-marketing with CFPB-ready audit trails — every partnership action is immutably logged. Client portal messages include wire-fraud warnings and block banking keywords. We do not sell phone, SMS, or A2P 10DLC as part of the $99 CRM.

Payment Processing

All payment processing handled by Stripe. Meridian never stores credit card numbers, CVVs, or full card details. PCI DSS compliance is maintained through Stripe's certified infrastructure.

Report a security concern

If you discover a security vulnerability, please contact us immediately at jared@osmeridian.com. We take all reports seriously and will respond within 24 hours.