Compliance Overview

Transparency about our compliance posture, certifications, data protection practices, and sub-processor ecosystem.

SOC 2 Type 2

In Progress

We are currently undergoing SOC 2 Type 2 audit with an independent third-party auditor. All Trust Service Criteria (TSC) controls have been implemented and are being monitored during the observation period.

Controls implemented12 / 12

Expected completion: Q3 2026. Report will be available to customers under NDA upon request.

GDPR Compliance

Compliant

As an EU-based service with data hosted in France, Real Estate OS is fully compliant with the General Data Protection Regulation (GDPR) and applicable EU data protection laws.

Lawful basis for processing documented for all data types
Data Processing Agreements (DPAs) with all sub-processors
Data Protection Impact Assessments (DPIAs) completed
Right to access, correction, deletion, and portability implemented
72-hour breach notification process documented
Data minimization and purpose limitation enforced
Cross-border transfer safeguards (EU data residency)
Records of processing activities maintained

Data Processing Agreement (DPA)

A pre-signed GDPR-compliant Data Processing Agreement is available for all customers. Enterprise customers may request a custom DPA. Contact us to obtain a copy.

Request DPA

Sub-processor List

The following third-party services process data on behalf of Real Estate OS. All sub-processors maintain SOC 2 Type 2 certification.

Sub-processorPurposeLocationSOC 2
StripePayment processingUSType 2
PlaidBank account linkingUSType 2
AnthropicAI document analysisUSType 2
ResendTransactional emailUSType 2
OVHInfrastructure hostingFrance (EU)Type 2
SentryError monitoringUSType 2

This list was last updated in March 2026. We will notify customers at least 30 days before adding new sub-processors.

Security Certifications Roadmap

Security Controls Implementation

Complete

All 12 SOC 2 Trust Service Criteria controls implemented

Q4 2025

SOC 2 Type 2 Audit

In Progress

Observation period with independent auditor

Q1 2026

SOC 2 Type 2 Report

Planned

Expected certification completion

Q3 2026

ISO 27001

Planned

Information security management system certification

Q1 2027

Compliance Inquiries

For questions about our compliance program, to request our SOC 2 report, or to discuss enterprise security requirements, contact our compliance team.

compliance@betonassets.com