How your papers are kept.
A home sale is full of documents worth protecting. Here is how we protect them, in enough detail to check.
Encrypted, scoped per sale, sealed when signed.Eight things that are actually done.
Encrypted, both directions
Your information is encrypted on its way to us (TLS) and while it's stored (at rest in the database and file storage). That covers documents, messages, photos and everything else in your Room.
Access is scoped to your sale, in the database
Every record is tied to one sale, and every person only sees what's theirs on that sale. These rules are row-level policies in the database itself, not only checks in the screens, so a bug in a page cannot show a row the rules forbid.
Signed documents are sealed
When a document is fully signed, we seal it and archive the signed PDF, the certificate, the audit trail, and each signer's consent record, together, in a folder that survives account deletion so the signature can be proven later.
We never see your card
Payments run on Stripe's own form. We are told a payment succeeded; the card number never touches our servers. There is no card kept on file, because there is nothing to bill again.
Links are hashed, and most are single-use
A sign-in link, a signing link, a booking link, an agent's hand-over link: each is a random token, stored only as a hash, and the sensitive ones stop working the moment they are used or claimed.
Your sale's mail is its own address
Mail for your sale arrives at an address that exists only for it. We never connect to your personal inbox, never hold its password, and never read it.
Your data isn't for sale
We don't sell personal information or share it for targeted advertising. Nothing in your Room is used to train AI models.
Problems reach a person
Server-side failures are reported with IDs and counts, not Room content. A security report from you goes to the same monitored inbox.
The rest of the answer.
Where it lives
Your Room lives in a managed database and file store run by Supabase, hosted in the United States, behind row-level policies that name your sale and your sign-in. The site and the Room are served by Vercel. Both are named, with what each receives, on the subprocessors page.
Who at Keighbor can see it
Keighbor staff don't have a standard login to your Room. If your written support request requires data access, we tell you what we'll review and let you know when we're done. Who can see what is the full table.
What survives deletion
One thing: a document you and other people signed, sealed, with its certificate, audit trail and consent record, kept so the signature can be proven later. Everything else goes when you delete your account. Deleting your data says why in full.
If something goes wrong
If we ever learn of a security incident that affects your information, we tell you: what happened, what of yours was involved, what we did, and what you can do, by email, as soon as we know enough to say something true, and within any period your state's law sets. The address for reporting a problem to us is hello@keighbor.com with “security” in the subject; a person reads it the same day. We do not run a bug bounty, and we do not take legal action against good-faith research that stays within your own account and tells us what it found.
Set up your Room.
Free to set up, encrypted from the first document, and yours to delete whenever you like.