Legal
Information Security Policy
Effective date: June 19, 2026
This policy outlines how OPTX protects the real estate data, credentials, vendor integrations, and generated analysis used inside the platform.
Purpose
This Information Security Policy describes the safeguards OPTX uses to protect real estate workflow data, client and seller context, property records, vendor data, generated analysis, and administrative access.
The policy is intended to support secure operation of OPTX and does not replace brokerage, MLS, vendor, legal, regulatory, or professional compliance requirements that may apply to a user or transaction.
Access Control
OPTX console access is restricted to authorized users through configured authentication controls.
Users must keep passwords, session access, API keys, report links, and other credentials confidential. Shared or unattended access should be avoided.
Access should be removed or rotated when a user no longer needs the system, when credentials may have been exposed, or when a vendor key changes.
Data Handling
OPTX may process property addresses, seller information, client goals, comparable sales, valuation opinions, rental data, market activity, parcel context, report URLs, notes, and generated draft content.
Users should enter only information they are authorized to use in the workflow and should avoid adding unnecessary sensitive personal information.
Outputs must be reviewed before they are shared with clients, brokers, lenders, appraisers, vendors, or other third parties.
Vendor And API Security
OPTX may connect to property data providers, AI model providers, hosting platforms, database services, map tile providers, and other configured third-party systems.
Vendor credentials should be stored in environment variables or managed secret stores, not in source code, public files, client-side bundles, screenshots, tickets, or shared documents.
Provider terms, licensing limits, retention restrictions, and permitted-use requirements must be reviewed before enabling a data source in production.
Application Controls
OPTX uses protected routes, HTTP-only authentication cookies, security headers, request validation, constrained payload parsing, and server-side API calls to reduce unauthorized access and unsafe data flow.
External URLs and generated content should be sanitized or validated before display, storage, or delivery in client-facing material.
Security-relevant changes should be tested before deployment, including authentication, protected API access, data-source behavior, and production smoke checks.
Secrets And Configuration
Production secrets, database URLs, API keys, authentication secrets, and vendor tokens must be treated as confidential.
Secrets should be rotated if they are accidentally committed, pasted into a public system, exposed in logs, shared in chat, or otherwise suspected to be compromised.
Development and production environments should use separate credentials when available, with the minimum permissions needed for each environment.
Retention And Disposal
CMA records, generated content, workspace notes, watchlist items, and related property data may be retained until deleted from the configured database or removed through operational processes.
When data is no longer needed, it should be deleted or de-identified when practical and consistent with business, legal, brokerage, and vendor obligations.
Removing a URL or reference from OPTX does not necessarily delete the underlying file or record from an external provider.
Monitoring And Incident Response
Operational logs, deployment checks, vendor responses, and application errors may be reviewed to troubleshoot issues and investigate suspicious activity.
Suspected unauthorized access, exposed credentials, unusual vendor usage, data leakage, or incorrect public deployment should be escalated promptly.
Reasonable response steps may include revoking sessions, rotating secrets, disabling affected integrations, reviewing logs, patching code, redeploying, notifying affected parties, and documenting corrective action.
User Responsibilities
Users are responsible for following applicable brokerage, MLS, Fair Housing, privacy, vendor, and client confidentiality requirements.
Users should verify property facts, valuation outputs, generated copy, and data-source results before relying on them in business decisions or client communication.
Users should report suspected security issues or urgent support needs through DRKNYT support at https://drknyt.com/urgentassistance.