Security
Real estate agents trust RealtyLens with walkthrough videos of properties and clients. Here is how we handle that responsibility.
Contact securitySecurity pillars
Six areas we focus on, with the concrete controls behind each one.
All data moving between your device and our servers travels over TLS 1.2 or higher. Files stored at rest — walkthrough videos, generated floor plans, enhanced photos, and derived analysis — are encrypted at the storage layer using AES-256.
Our API runs on DigitalOcean with Nginx in front for TLS termination. Property files are stored in Cloudflare R2. Database is Neon Postgres, a managed serverless provider. None of these are self-hosted, which means each vendor's security practices layer on top of ours.
Every API key and credential is scoped to the minimum permission needed. Infrastructure secrets rotate on a fixed schedule. Internal admin endpoints require a separate bearer token that is not part of normal user auth flows.
Each user's jobs, analyses, and saved searches are scoped to their account ID and enforced at the query level. API routes verify ownership before returning data — a request for another user's report returns 403, not the data.
Neon Postgres provides point-in-time recovery with automated backups. Cloudflare R2 stores files with built-in redundancy. We test restoration periodically to make sure backups are usable, not just present.
We welcome security research. If you find a vulnerability, email us at tryrealtylens@gmail.com with enough detail to reproduce it. We will acknowledge within 2 business days and keep you updated as we work through it.
Privacy and data handling
RealtyLens processes the walkthrough videos you upload and the analysis data derived from them — room layouts, condition scores, listing copy, floor plan SVGs, and extracted photos. We also store account information (name, email, subscription tier) and usage logs for billing and abuse prevention.
Uploaded videos and derived files are retained while your account is active and for a reasonable period after account closure to support dispute resolution. Usage logs are retained for up to 12 months. You can request deletion of your data at any time by emailing us.
The property analyses, floor plans, listing copy, and photos generated from your videos belong to you. We do not use them to train AI models or share them with third parties outside of the AI providers required to run the analysis pipeline.
Video frames and prompts are sent to one or more AI model providers (Google Gemini, OpenAI, Anthropic, Cerebras) for analysis. File storage is handled by Cloudflare R2. Each provider is bound by their own data processing terms.
For full details, see our Privacy Policy and Terms of Service.
We are a small team and our security program is growing alongside the product. Items we are working toward include a formal third-party penetration test, a structured vulnerability disclosure program, and SOC 2 Type II certification. These are goals, not current claims.
If you believe you have found a security issue in RealtyLens, please let us know. We take all reports seriously and aim to acknowledge within 2 business days.
tryrealtylens@gmail.comPlease include enough detail to reproduce the issue. We will keep you updated as we investigate and resolve it.
We are happy to answer questions from enterprise buyers, compliance teams, or curious agents.
Get started