Security & compliance details
Last updated: July 7, 2026
Our security commitment
Housingstreet Marketing and Consulting Private Limited (HousingStreet) builds software that holds listing photos, client phone numbers, deal notes, and payment relationships. We treat that responsibility seriously — not as a marketing checkbox.
Security is designed into our multi-tenant architecture: every API route authenticates the caller, scopes database queries to a tenant, and checks permissions before returning or changing data.
Infrastructure
- Production workloads run on enterprise cloud infrastructure with automated backups
- TLS 1.2+ for all traffic between your browser and our servers
- Encryption at rest for databases and object storage
- Secrets and API keys stored outside application code, rotated on compromise
- Separate environments for development, staging, and production
Access control
- Role-based access control (RBAC) with granular permissions per feature
- Multi-office scoping for enterprise brokerages
- Optional SSO on eligible plans
- Session management with refresh tokens, idle timeouts, and MFA support
- Audit logs for sensitive settings and team actions on supported plans
Payment security
Card payments are processed by Stripe, a PCI DSS Level 1 certified provider. HousingStreet does not store full card numbers, CVV, or magnetic-stripe data on our servers. We receive subscription status, customer IDs, and limited billing metadata needed to provision your account.
Application security practices
- Input validation on API boundaries (Zod schemas)
- Password hashing with industry-standard algorithms
- Rate limiting and abuse detection on authentication endpoints
- Content Security Policy and secure cookie flags in production
- Dependency monitoring and security patches applied on a prioritized basis
Incident response
We maintain an internal incident response process. If we confirm a breach that materially affects your workspace data, we will notify account owners without undue delay and describe remedial steps. Report suspected vulnerabilities to security@housingstreet.com — we appreciate responsible disclosure.
Compliance posture
We align with GDPR principles for EU/UK customers, India's Digital Personal Data Protection Act where applicable, and common SaaS security expectations from payment partners. We have not yet completed SOC 2 Type II or ISO 27001 certification; we will publish credentials when earned — we do not display badges we have not achieved.
What you can do
- Use strong, unique passwords and enable MFA when available
- Limit admin roles to people who need them
- Remove team members promptly when they leave your agency
- Only publish property and client data you are legally allowed to process
Contact
Security inquiries and vulnerability reports: security@housingstreet.com. Legal entity: Housingstreet Marketing and Consulting Private Limited, CIN U67100DL2020PTC367725, H. No. B-165, Ambedkar Colony, Gali No. 1, Chattarpur, South Delhi, New Delhi – 110074, India.