SECURITY & COMPLIANCE

Trust, written into the platform - not bolted on.

Saleable handles the most sensitive data in a real estate transaction. Buyer ID, banking details, signed contracts, and APS metadata. Here's how we protect it.

Six controls every IT team asks about

Compliance

PIPEDA and GDPR compliant. SOC 2 Type II in progress (target completion: end of 2026). Data Processing Addendum (DPA) available on request.

Data residency

Buyer data is stored on Canadian-hosted infrastructure by default. Multi-region data residency is available on Enterprise plans.

Encryption

AES-256 at rest. TLS 1.3 in transit. Field-level encryption for personally identifiable information (SIN, driver's license, banking details).

Access controls

Role-based permissions for builder, sales, brokerage, and admin roles. SSO (SAML / OIDC) on Enterprise. MFA enforced for admin roles.

Backup & DR

Hourly incremental backups, daily full backups, point-in-time restore. Documented RPO/RTO available under NDA.

Privacy & DPA

Privacy policy and DPA available on request. Buyer data is exportable or deletable on request to comply with PIPEDA right-to-access and GDPR right-to-be-forgotten.

Need our DPA, PIPEDA statement, or security questionnaire?

Email security@saleable.ca and we'll send the docs same business day.