Your book of business is your livelihood. We treat it that way.

CertiHomes was built security-first — verified sign-in, isolated tenants, and no card data ever touching our servers. Here’s exactly how.

Sign-in you can trust

  • Google-verified sign-in. You sign in with Google — we never store or even see a password. Sign-in runs on a Google-published OAuth app (no “unverified app” warnings).
  • Signed, HTTP-only sessions. Your session is a tamper-proof, HTTP-only token — it can’t be read or forged by scripts in the browser.
  • More sign-in options coming (Microsoft, Apple, email) — same standard.

Your data is yours, and only yours

  • Per-tenant isolation. Every brokerage/team is its own walled tenant. Your contacts, deals, and campaigns are scoped to your organization — one account can’t see another’s data.
  • You can export or delete. Your contacts and pipeline are yours to take with you, any time. No lock-in.
  • We don’t sell your data. CertiHomes runs on owned infrastructure — your client list is never a product we resell.

Payments handled by Stripe — card data never hits our servers

PCI by design. All billing runs through Stripe-hosted Checkout and the Billing Portal. Card numbers go straight to Stripe; CertiCRM never sees or stores them.

Marketing that respects the law (and your reputation)

  • CAN-SPAM built in. Every email carries a real unsubscribe link and your physical address. Unsubscribes are honored automatically.
  • Per-channel opt-out. Email and SMS consent are tracked separately — an SMS STOP never accidentally kills someone’s email eligibility, and vice-versa (CAN-SPAM vs. TCPA).

Encrypted, monitored, owned

  • Encrypted in transit — HTTPS everywhere.
  • Owned infrastructure. We run on our own hardware and cloud — not a thin reseller layer.

Frequently asked questions

Do you store my password?

No. Sign-in is Google OAuth — we never receive or store a password.

Can another brokerage see my contacts?

No. Data is isolated per tenant/organization — one account can't see another's contacts, deals, or campaigns.

Where does my payment info go?

Directly to Stripe. All billing runs through Stripe-hosted Checkout and the Billing Portal — CertiCRM never sees or stores card data.

Can I get my data out?

Yes — you can export your contacts and pipeline any time. There's no lock-in.

Are my marketing emails compliant?

Yes. Every email carries a real unsubscribe link and a physical address (CAN-SPAM), honored automatically. Email and SMS opt-outs are tracked separately, so an SMS STOP never accidentally kills someone's email eligibility.