SECURITY & COMPLIANCE
Trust, written into the platform - not bolted on.
Saleable handles the most sensitive data in a real estate transaction. Buyer ID, banking details, signed contracts, and APS metadata. Here's how we protect it.
Six controls every IT team asks about
Compliance
PIPEDA and GDPR compliant. SOC 2 Type II in progress (target completion: end of 2026). Data Processing Addendum (DPA) available on request.
Data residency
Buyer data is stored on Canadian-hosted infrastructure by default. Multi-region data residency is available on Enterprise plans.
Encryption
AES-256 at rest. TLS 1.3 in transit. Field-level encryption for personally identifiable information (SIN, driver's license, banking details).
Access controls
Role-based permissions for builder, sales, brokerage, and admin roles. SSO (SAML / OIDC) on Enterprise. MFA enforced for admin roles.
Backup & DR
Hourly incremental backups, daily full backups, point-in-time restore. Documented RPO/RTO available under NDA.
Privacy & DPA
Privacy policy and DPA available on request. Buyer data is exportable or deletable on request to comply with PIPEDA right-to-access and GDPR right-to-be-forgotten.
Need our DPA, PIPEDA statement, or security questionnaire?
Email security@saleable.ca and we'll send the docs same business day.