Security & trust

Your portfolio deserves more than a password.

EstateIQ is designed with organization-scoped access, permission-checked files, traceable financial records, and clear limits around how AI works with your data.

Private portfolio workspace

One access model across the product.

Access scoped

Verified member

Signed in

Permission checked

Ocean View Rental

Organization workspace

Buildings
Leases
Ledger
Documents

EstateIQ AI

Same permissions. Grounded in accessible records.

Access is evaluated before portfolio records or files are returned.

Your portfolio

Security follows the record.

The same boundary follows buildings, units, tenants, leases, money, and documents, so protection does not disappear when the workflow changes.

01

Your workspace sets the boundary

Buildings, units, tenants, leases, financial records, and documents are organized within an organization workspace.

02

Access is permission-aware

Authentication establishes identity. Active membership and authorization determine what that identity can access.

03

Financial history stays traceable

Balances come from charges, payments, and allocations. Related financial writes use database transactions so they succeed or roll back together.

BuildingsUnitsTenantsLeasesLedgerDocuments

10 minutes

Default production access-token lifetime

Rotating

Refresh tokens are replaced after use

Blacklisted

Invalidated refresh tokens are rejected

Sensitive workflows

Connected, without creating a back door.

Documents, AI, and subscription billing each have a defined role. None of them should become a shortcut around the controls protecting the rest of the portfolio.

Documents

Files are not treated like public links.

Production uploads use private S3-compatible storage. Downloads are permission-checked, and generated links expire after five minutes by default.

EstateIQ AI

AI explains records. It does not replace them.

The AI layer is read-only against financial records. Deterministic tools prepare accessible portfolio facts before AI explains them in plain language.

Subscription billing

Billing events are verified before they change access.

Stripe hosts checkout and billing management. EstateIQ validates each webhook signature before accepting a subscription change, and card data does not pass through the EstateIQ application.

Hosted by Stripe

Plain-language trust

Specific controls beat impressive-sounding claims.

We explain the controls EstateIQ is designed around and avoid certifications, guarantees, or compliance claims the product has not earned.

What we document

Controls you can understand

Short-lived, rotating sessions
Organization-scoped access
Five-minute signed document links
Read-only AI against financial records

What we do not claim

Promises without proof

Vague bank-grade language
Undocumented certifications
Unverified compliance status
Absolute security guarantees

EstateIQ security

Your portfolio should feel connected, not exposed.

Have a security or trust question? We will explain the controls EstateIQ has today, plainly and directly.