Security
Closing Time handles contracts, dates and client contact details. This page lists what protects them today and what we do not claim yet.
In Place Today
- Encrypted connections
- All traffic uses HTTPS.
- Password storage
- Passwords are stored as one-way bcrypt hashes. We never see or store your password.
- Two-step sign-in
- Turn on an authenticator app code in Closing Time under Resources, Security. Recovery codes are provided and each works once.
- Sessions
- Sign-in cookies are marked HTTP-only and secure, and cannot be read by page scripts.
- Abuse protection
- Sign-in and account requests are rate limited. Requests that change security settings, API keys, webhooks, imports and backups are checked against allowed origins, and sign-in cookies use SameSite protection.
- Your own data only
- Every request is tied to your signed-in account. API keys are shown once, stored as hashes, and can be revoked at any time.
- Signed webhooks
- Every webhook message is signed with a secret only you hold, so your system can confirm it came from Closing Time.
- Audit trail
- Deal changes, documents, requests and messages are recorded in a time-stamped activity history.
- Backups and export
- Monthly backups and full exports in open formats are available from Data And Backups.
Not Yet
- SOC 2 or other third-party certification. We have not been audited and do not claim to be.
- An independent penetration test. None has been done yet.
- Two-step sign-in is optional. It is not yet required for every account.
Report A Concern
Email tawanna@myrealtyline.com. Please include steps to reproduce.