Security & Trust
Real estate transactions involve sensitive financial and personal data. Here's exactly what we do to protect yours.
Your Money
Aletheia never holds, processes, or passes through any transaction funds. Earnest money goes directly to the title or escrow company — not through us.
- No funds through Aletheia — We are a transaction platform, not a payment processor. No money ever moves through our systems.
- Wire fraud verification before closing — When a buyer closes through Aletheia, they must verify the title company's wire instructions by phone — using a number they look up independently, not one from an email — before the sale can be marked closed. That step can't be skipped. Aletheia never holds, transfers, or verifies wire instructions itself.
Document Access
- Visible only to the parties — Offers, purchase agreements, and transaction documents are accessible only to the buyer and seller in that transaction. Access is enforced on the server; there is no shareable link or role bypass.
- Generated from your inputs — Purchase agreements are generated from the terms you and the other party enter. The signed document becomes part of your transaction record and cannot be modified after signing.
Encryption
- Encryption in transit — All data is encrypted in transit using TLS 1.3.
- Password hashing — Passwords are hashed using bcrypt with a cost factor of 12. We never store plain-text passwords.
- Database encryption — All data at rest is encrypted via our hosting provider's infrastructure-level encryption.
Authentication
- Email verification — All accounts must verify their email address before submitting offers.
- Session expiration — Sessions expire automatically after 8 hours.
- Rate limiting — Login attempts, password resets, and API calls are rate-limited to prevent abuse.
Signatures & Audit Trail
Every significant action is logged with a tamper-resistant audit trail — a complete, unbroken record of the transaction process.
- Drawn signatures — Electronic signatures are captured as a drawn image paired with the signer's IP address, timestamp, and user ID.
- SHA-256 document hashes — Every signed document gets a SHA-256 fingerprint at the moment of signing. If the document were altered afterward — even by a single character — the fingerprint would no longer match. The alteration would be provable.
- Timestamped actions — Every offer submission, counter, acceptance, and rejection is logged with precise timestamps.
- IP and device logging — The IP address and user agent are recorded for each significant action.
- Tamper-evident chain — Audit entries are cryptographically hash-chained: each entry locks in a hash of the previous one. Any attempt to alter, delete, or reorder a past record breaks the chain and is immediately detectable.
Compliance
E-SIGN Act
Signatures on Aletheia are executed under the federal Electronic Signatures in Global and National Commerce Act (15 U.S.C. § 7001). Each is captured with the signer's drawn image, IP address, timestamp, and user ID.
UETA
Signatures are also executed under Utah's Uniform Electronic Transactions Act (Utah Code § 46-4-101), which governs electronic transactions in the state.
Important: Aletheia is not a licensed real estate broker. We provide a technology platform for offer submission and do not provide legal or real estate advice. Consult a licensed professional for legal or transactional guidance specific to your situation.
Your Data
- No data sales — Your personal and financial information is never sold to third parties.
- Account deletion — Delete your account anytime from Account Settings. Deletion anonymizes your personal information (name, email, contact details); completed transaction records are kept for six years.
- Retention — Six years reflects Utah's written contract statute of limitations (Utah Code § 78B-2-309) — our choice of how long to keep records available for dispute resolution. No law requires it.
For full details, see our Privacy Policy.
Have security questions or want to report a vulnerability?
Contact Us