\n\n Trust Center — Realty51 | Security, Certifications & Data Practices
Platform Integrity

Trust Center

Every claim, partner, and data point on Realty51 is verified. Here is how we build and maintain the trust of buyers, sellers, and institutional partners across Southeast Asia.

Our Trust Foundation

How We Protect You

🔒
TLS 1.3 Everywhere
All connections are encrypted in transit using TLS 1.3. HTTP traffic is automatically redirected to HTTPS with HSTS preloading.
🛡
Cloudflare DDoS Protection
All traffic routes through Cloudflare's global edge network with Bot Fight Mode and Web Application Firewall rules active 24/7.
🔑
Prepared Statements Only
Every database query uses parameterised prepared statements. No raw SQL concatenation. SQL injection is structurally impossible.
🚦
Rate Limiting
API endpoints enforce per-IP rate limits. Repeated failed authentication attempts trigger automatic lockout to prevent brute-force attacks.
👁
Continuous Monitoring
Sentry error tracking, Prometheus metrics, and Grafana dashboards monitor platform health in real time with alerting under 60 seconds.
💾
Daily Encrypted Backups
Database backups run nightly with encrypted offsite storage. Recovery point objective (RPO) is less than 24 hours.

Our Certifications

🔐
Cloudflare Verified
Active
DDoS protection, WAF, and CDN verification active since 2022.
🌐
SSL / TLS Certificate
Active
Let's Encrypt TLS 1.3 certificate, auto-renewed. HSTS enforced.
📋
ISO 27001
In Progress
Information security management audit in preparation. Target: Q4 2026.
🔍
SOC 2 Type II
Planned 2027
Service Organisation Control audit planned following ISO 27001 completion.
🇪🇺
GDPR Compliance
In Progress
Data processing agreements active for EU users. DPA review with legal counsel ongoing.
🇹🇭
PDPA Compliance
Active
Thailand Personal Data Protection Act compliance implemented across all user-data flows.

Your Data Rights

We do not sell your personal data
Realty51 does not sell, rent, or broker user data to third parties. Analytics are anonymised and aggregated before any external sharing.
Right to access and erasure
You can request a full export of your data or permanent account deletion by emailing [email protected]. Requests are fulfilled within 30 days.
Property listing data is verified
All active listings are cross-referenced against three data sources before publication. Title deed references and agent credentials are checked against the Department of Lands registry where available.
Financial data uses regulated partners only
Mortgage, insurance, and payment services are provided exclusively by licensed financial institutions. Realty51 does not hold or process payment card data directly — all card processing is handled by Stripe with PCI-DSS Level 1 certification.
Transparent AI usage
Where AI is used to generate property descriptions, market analysis, or valuation estimates, this is explicitly labelled. AI outputs are reviewed by human analysts before publication in market reports.