Your book of business is your livelihood. We treat it that way.
CertiHomes was built security-first — verified sign-in, isolated tenants, and no card data ever touching our servers. Here’s exactly how.
Sign-in you can trust
- Google-verified sign-in. You sign in with Google — we never store or even see a password. Sign-in runs on a Google-published OAuth app (no “unverified app” warnings).
- Signed, HTTP-only sessions. Your session is a tamper-proof, HTTP-only token — it can’t be read or forged by scripts in the browser.
- More sign-in options coming (Microsoft, Apple, email) — same standard.
Your data is yours, and only yours
- Per-tenant isolation. Every brokerage/team is its own walled tenant. Your contacts, deals, and campaigns are scoped to your organization — one account can’t see another’s data.
- You can export or delete. Your contacts and pipeline are yours to take with you, any time. No lock-in.
- We don’t sell your data. CertiHomes runs on owned infrastructure — your client list is never a product we resell.
Payments handled by Stripe — card data never hits our servers
PCI by design. All billing runs through Stripe-hosted Checkout and the Billing Portal. Card numbers go straight to Stripe; CertiCRM never sees or stores them.
Marketing that respects the law (and your reputation)
- CAN-SPAM built in. Every email carries a real unsubscribe link and your physical address. Unsubscribes are honored automatically.
- Per-channel opt-out. Email and SMS consent are tracked separately — an SMS STOP never accidentally kills someone’s email eligibility, and vice-versa (CAN-SPAM vs. TCPA).
Encrypted, monitored, owned
- Encrypted in transit — HTTPS everywhere.
- Owned infrastructure. We run on our own hardware and cloud — not a thin reseller layer.
Frequently asked questions
Do you store my password?
- No. Sign-in is Google OAuth — we never receive or store a password.
Can another brokerage see my contacts?
- No. Data is isolated per tenant/organization — one account can't see another's contacts, deals, or campaigns.
Where does my payment info go?
- Directly to Stripe. All billing runs through Stripe-hosted Checkout and the Billing Portal — CertiCRM never sees or stores card data.
Can I get my data out?
- Yes — you can export your contacts and pipeline any time. There's no lock-in.
Are my marketing emails compliant?
- Yes. Every email carries a real unsubscribe link and a physical address (CAN-SPAM), honored automatically. Email and SMS opt-outs are tracked separately, so an SMS STOP never accidentally kills someone's email eligibility.