Data Security

How RevRE protects
your data.

RevRE handles sensitive operational and financial data for multifamily portfolios across the country. This page outlines the technical and organizational controls we have in place to ensure that data is protected at every layer — from the moment it's extracted from your PMS to the moment it's delivered to your team.

SOC 2 Compliant Encrypted in transit & at rest Read-only PMS access
Overview

Security is foundational, not an afterthought.

RevRE processes sensitive operational and financial data on behalf of multifamily operators, ownership groups, and investment managers. The trust our customers place in us when they connect their property management systems is not taken lightly. Our security architecture is designed from the ground up to protect that data at every layer — infrastructure, application, access, and process.

This page describes the specific technical and organizational controls RevRE maintains. If you have questions beyond what's covered here, or need documentation for a vendor security review, our team is available to assist.

SOC 2 Compliant
Independently audited against the Trust Services Criteria for security, availability, and confidentiality.
Encryption everywhere
All data encrypted in transit (TLS 1.2+) and at rest (AES-128+). No exceptions.
Read-only PMS access
RevRE can only read from your source systems — it cannot write, modify, or delete source data under any circumstances.
Continuous monitoring
Infrastructure and application logs monitored continuously. Anomalous activity triggers automated alerts and review.

Compliance

SOC 2 Compliance

SOC 2 — Independently audited security controls
RevRE maintains SOC 2 compliance, meaning our data handling practices, security architecture, and operational controls have been reviewed and validated by an independent third-party auditor against the AICPA's Trust Services Criteria.

SOC 2 compliance covers five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. RevRE's controls are designed to address each of these categories as they apply to a multifamily data platform.

What this means for customers: Your data is handled under a documented, audited control framework — not just internal policy.

Access Management

Data Access Controls

Access to customer data — both within RevRE's systems and within the customer-facing platform — is governed by strict least-privilege controls. This means every person and every system component receives only the permissions required to perform its specific function, and nothing more.

Least-privilege principle: No RevRE employee has standing access to customer data. Access is granted on a case-by-case basis, logged, reviewed, and time-limited to the minimum necessary to resolve a specific issue or fulfill a specific request.
  • Customer-facing access is controlled through role-based permissions configured by each customer's administrator
  • Multi-factor authentication (MFA) is required for all RevRE internal system access
  • All internal access to customer data is logged with user identity, timestamp, and action taken
  • Access logs are retained and available for audit review
  • Permissions are reviewed periodically and revoked immediately upon role change or offboarding

Customer administrators control which team members have access to which properties and which data views within the RevRE platform. RevRE does not have access to customer-configured permissions and cannot override them.

Data Protection

Encryption

RevRE encrypts all data in transit and at rest using current industry standards. Encryption is not optional or configurable — it applies to all data flowing through the RevRE platform without exception.

In transit — TLS 1.2+
All data transmitted between RevRE systems, PMS sources, and customer endpoints uses TLS 1.2 or higher. Unencrypted connections are rejected.
At rest — AES-128+
All stored data — including database records, file exports, and backup snapshots — is encrypted at rest using AES-128+.
Key management
Encryption keys are managed through a dedicated key management service, with rotation policies and access controls separate from application access.
API security
All API endpoints require authenticated, encrypted connections. API keys are scoped, rotatable, and never exposed in client-side code or logs.
Infrastructure

Infrastructure Security

RevRE's infrastructure is hosted on enterprise-grade cloud infrastructure with security controls inherited from and built on top of the provider's own compliance certifications. Our deployment architecture is designed to isolate customer environments, minimize attack surface, and maintain availability.

  • Production infrastructure is logically isolated from development and staging environments
  • Network access to production systems is restricted through firewalls and security groups — no public access to database or internal service layers
  • Infrastructure changes require code review and are deployed through automated pipelines with audit logging
  • Vulnerability scanning runs continuously on application dependencies and infrastructure components
  • Penetration testing is conducted periodically by qualified third parties
  • Automated backups run on a regular schedule with tested restoration procedures
  • Infrastructure is monitored 24/7 with automated alerting for anomalous activity, availability degradation, or security events
Source Connections

PMS Connection Security

When RevRE connects to a customer's property management system, it does so through a read-only credential — either via secure API integration or encrypted SFTP. This is a hard architectural constraint, not a configuration option.

RevRE cannot write to your source systems. The credentials provided for PMS connections are read-only at the source system level. RevRE has no ability to create, modify, delete, or otherwise alter data in your PMS, your accounting system, or any other connected source.
  • PMS credentials are stored encrypted and are never exposed in logs, responses, or user interfaces
  • Credentials are scoped to the minimum access necessary — read-only, and where possible, limited to specific data types
  • SFTP connections use dedicated credentials per customer
  • API connections use secure OAuth or token-based authentication with provider-level access controls
  • Connection activity is logged and anomalous patterns (unexpected volumes, unusual timing) trigger review
Incident Response

Incident Response

RevRE maintains a documented incident response plan that defines how security events are identified, contained, investigated, and resolved. The plan is reviewed and updated regularly, and key components are tested through tabletop exercises.

  • Detection: Automated monitoring systems alert the security team to potential incidents in real time. All alerts are triaged, with severity classification determining response priority and timeline
  • Containment: Affected systems or accounts are isolated as quickly as possible to limit blast radius while investigation proceeds
  • Investigation: Root cause analysis is conducted for all confirmed security incidents, with findings documented internally
  • Notification: Customers whose data may have been affected are notified promptly — within the timeframe required by applicable law and our contractual obligations — with a clear description of what occurred, what data may have been involved, and what steps are being taken
  • Remediation: Fixes are implemented, tested, and verified before affected systems are returned to production
  • Post-incident review: Every confirmed security incident results in a formal post-incident review to identify systemic improvements

To report a suspected security issue, contact us through the form below. Security reports are treated with urgency and handled by qualified personnel.

People & Process

Employee Security Controls

Security is a responsibility that extends to every member of the RevRE team. Our employee security program ensures that the people handling customer data understand their obligations and operate within a controlled framework.

  • All employees undergo background screening as a condition of employment
  • New employees complete security awareness training before receiving access to any production systems
  • Annual security training is required for all staff, with role-specific training for those with elevated access
  • All employees sign confidentiality agreements covering customer data and business information
  • Access to production systems is granted based on role necessity, reviewed periodically, and revoked immediately on offboarding
  • Workstation security policies require disk encryption, screen lock, and managed device configurations
  • MFA is required for all internal system access without exception
Security questions or SOC 2 report requests?
Our team handles security questionnaires and SOC 2 report requests. We typically respond within 1–2 business days.