Trust & Security

Security you can build on.

KMF Commercial Real Estate is the operating system commercial brokers run their business on — leads, contacts, deals, and communications. We take the security of that data seriously. This page describes the controls in place today and where we're headed.

This page is maintained by KMFCRE. It reflects current practices and is not an independent audit report or certification. Last updated: July 8, 2026.

Compliance roadmap

KMFCRE is actively preparing for formal SOC 2 Type II and ISO/IEC 27001 attestations. We are aligning our policies, access controls, monitoring, and vendor management program to those frameworks today, and will publish audit reports here once completed.

SOC 2 Type IIIn progress

Trust Services Criteria — Security

ISO/IEC 27001In progress

Information Security Management System

Enterprise customers evaluating KMFCRE can request our current security questionnaire and roadmap by emailing info@kmfcre.com.

How we protect your data

The controls below are enabled on the platform today. They're the foundation the formal SOC 2 and ISO 27001 programs are being built on.

Encryption in transit

All traffic to and from the platform is served over HTTPS/TLS. Custom domains are provisioned with managed certificates.

Encryption at rest

Customer data is stored in managed Postgres with encryption at rest handled by the underlying cloud provider.

Row-level access control

Every table enforces row-level security policies so users can only read or modify data they're authorized to see.

Authentication & MFA

Email/password and Google sign-in with support for multi-factor authentication and session timeout re-authentication.

Managed infrastructure

Hosted on modern cloud infrastructure with automated backups, isolated environments for development and production, and least-privilege service credentials.

Audit trails

Policy acknowledgements, disclaimer acceptances, tool usage, and administrative actions are logged with timestamp, IP, and user agent.

Monitoring & alerting

Application errors, authentication anomalies, and edge-function failures are monitored and surfaced to the engineering team.

Change management

Application changes flow through code review, automated typecheck, and preview environments before reaching production.

U.S. data residency

The platform operates from the United States and is intended for U.S. customers. Data is processed in the U.S.

Access control

Administrative access to production systems is restricted to a small number of engineering staff and is protected by multi-factor authentication. Access is granted on a least-privilege basis and reviewed periodically.

Application user roles are stored in a dedicated table (never on the user profile) and enforced by security-definer database functions to prevent privilege-escalation patterns.

Data handling & retention

We retain customer data for as long as the account is active and as required to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. On account closure or deletion request, data is deleted or de-identified on a reasonable schedule, subject to legal retention requirements.

See our Privacy Policy for full details on collection, use, and user rights.

Subprocessors

We rely on established subprocessors for cloud hosting and database, payment processing, email and SMS delivery, mapping and property data, and AI features. Each subprocessor is engaged under a written agreement that restricts their use of customer information to providing services on our behalf.

A current subprocessor list is available on request from info@kmfcre.com.

Incident response

We maintain an incident response process covering detection, containment, notification, and post-incident review. In the event of a confirmed incident affecting customer data, we will notify affected customers without undue delay and in accordance with applicable law.

To report a suspected security issue or vulnerability, email info@kmfcre.com with details and reproduction steps. Please do not publicly disclose issues before we have had a reasonable opportunity to investigate and remediate.

Payments & PCI

Subscription and usage-based charges are processed by Stripe. Full payment-card details are collected and handled by Stripe under their PCI DSS Level 1 attestation and are never stored on KMFCRE servers.

Shared responsibility

Security is a partnership. KMFCRE is responsible for the platform, infrastructure, and the controls described on this page. Customers are responsible for using strong unique passwords, enabling MFA, managing team-member access, protecting API keys stored in their account, and complying with laws that apply to how they contact consumers (TCPA, CAN-SPAM, state privacy laws).

Security & compliance contact

Have a security question?

Vendor reviews, security questionnaires, subprocessor lists, DPA requests, or to report a suspected vulnerability — we'll get back to you.

info@kmfcre.com