Security & Privacy

Your documents are
safe with us.

estats is built for Canadian real estate professionals who need to trust the platform handling their clients' most important documents. Here's exactly how we protect you.

Encrypted in transit
TLS 1.2+ on every connection
Canadian hosting
Data never leaves Canada
PIPEDA-aligned
Canadian privacy law compliance
PCI DSS payments
Billing via Stripe โ€” we never store cards

Infrastructure

Canadian data residency.

๐Ÿ‡จ๐Ÿ‡ฆ

Proudly made in Canada

Estats product is developed in Canada. Your data is governed by Canadian privacy law (PIPEDA) at all times.

DigitalOcean Canada
Servers in Canadian data centres. No data leaves the country through our infrastructure.
Encrypted at rest
Sensitive fields are encrypted in the database. Passwords are hashed using bcrypt โ€” never stored in plaintext.
TLS everywhere
All connections to estats use HTTPS with TLS 1.2+. No unencrypted data in transit.
Audit logging
Server-side audit logs record key actions. Signing events are timestamped and IP-stamped for audit trail integrity.

E-Signature

How the signing process works.

1
Unique signing link
Each signer receives a unique, time-limited token URL. The token is cryptographically random (UUID v4) โ€” it cannot be guessed or brute-forced.
2
E-SIGN consent disclosure
Before signing, every signer must explicitly accept the E-Sign Consumer Disclosure and Consent โ€” the same requirement mandated by the Electronic Transactions Act (BC) and Canada's electronic commerce laws.
3
Signature adoption
Signers draw, generate, or type their signature. A per-token watermark is embedded in the signature image. The adopted signature is stored securely.
4
Document review & signing
The signer reviews the full document and places their signature and initials on each required field before submitting.
5
Audit trail & certificate
Upon completion, estats generates a certificate of completion containing signer name, email, IP address, device info, and timestamps for every action. The executed PDF and certificate are stored for 7 years.
6
Distribution to all parties
The executed document is automatically distributed to all signing parties by email. No party can modify the document after all signatures are collected.

Payments

We never touch your card.

Stripe payment processing
All payments are handled by Stripe, a PCI DSS Level 1 certified processor. Card numbers are entered directly into Stripe's secure fields โ€” estats never sees or stores them.
Automatic tax compliance
Stripe Tax automatically calculates and collects GST, HST, and applicable provincial taxes based on your billing address.

Access & accounts

Account protection.

Email verification
Every account requires email verification before access is granted. We also support magic-link login for passwordless, secure access.
Organization-scoped data
Data is scoped to your organization. Users within one account cannot access another organization's documents, properties, or contacts.
Google OAuth
Sign in with Google is supported. We request only the minimum necessary scopes (email and profile). We never request access to your email content.
Privilege-based access control
Feature access is controlled by account privilege level. Trial, paid, and admin roles each have defined boundaries enforced server-side.

Compliance & legal

Built for Canadian law.

estats is designed with Canadian privacy and electronic commerce legislation in mind:

โœ“ PIPEDA (Personal Information Protection)
โœ“ Electronic Transactions Act (BC)
โœ“ CASL (anti-spam for email)
โœ“ BC RTB form compliance
โœ“ PCI DSS (via Stripe)
โœ“ Canadian data residency

Note: Compliance badges reflect our technical and operational design practices. estats is not a certified compliance body and does not provide legal advice. Consult a qualified attorney for legal guidance.

Contact

Report a security issue.

If you believe you have found a security vulnerability in the estats platform, please report it responsibly by emailing security@estats.ca. We take all reports seriously and will respond within 48 hours. We ask that you give us reasonable time to investigate and address the issue before any public disclosure.