Security at Estateably
At Estateably, the security and privacy of your client data is our top priority.
We’ve built our product according to the highest security standards and industry best practices. Estateably meets SOC2 compliance standards, and we regularly conduct comprehensive audits of our applications, systems, and networks to ensure that your data is always protected.
View & Request Policy Documents
Compliance
Request a copy of our audit reports and penetration testing results.
SOC 2 Type 2
Final SOC 2 Type 2 audit report
PCI
Full PCI-DSS audit report

Penetration Testing
Annual penetration testing results
Resources
IT Infrastructure & Service Delivery Policy
Information Security Policy
Penetration Test Report
PCI DSS AOC
SOC 2 Type 2 Full Report
PCI DSS Full Report
Terms of Service
Privacy Policy
Business Continuity Plan
Disaster Recovery Plan
FAQs
Answers to Estateably's commonly asked security questions.
Product security & reliability
Estateably offers many security features, including SAML SSO and Role-based access controls, to ensure best-in-class protection.
Does Estateably offer Single sign-on (SSO)?
Estateably supports single sign-on (SSO). By using the customer’s existing identity management solution, Estateably provides an easy and secure way for companies to manage their team members’ access. Estateably supports identity providers like Google G Suite, Azure Active Directory, OneLogin, and Okta. Estateably also supports both SAML and OAuth-based OpenID Connect.
Does Estateably support Role-based access control (RBAC)?
Estateably supports role-based access control, which means the access of team members within an organization is dictated by their role (eg. viewer, collaborator, editor, or administrator). Administrators can edit or create roles and assign team members specific roles or revoke access using the Estateably account dashboard.
What is Estateably's uptime?
Estateably has 99% or higher uptime.
Please visit our status page for more information at: https://estateably.statuspage.io/
Does Estateably perform Disaster Recovery Exercises?
Estateably conducts an annual Disaster Recovery Exercise to verify the resilience of our systems and processes and ensure rapid recovery during disruptions. This exercise includes simulating different disaster scenarios to evaluate the effectiveness of our disaster recovery plans and procedures.
Cloud Security
Estateably’s security and availability architecture is built on top of SOC2 controls to enable best practice protection controls, implemented based on industry standards.
Logical Access
Access to the Estateably Production Network is restricted by an explicit need-to-know basis, utilizes least privilege, is frequently audited and monitored, and is controlled by our Operations Team. Employees accessing the Estateably Production Network are required to use multiple factors of authentication and complete extensive background checks along with many technical and administrative controls.
What permissions and authentication are in place?
Access to customer data is limited to authorized privileged employees who require it for their job responsibilities. Estateably runs a zero-trust corporate network. We have SAML Single Sign-on (SSO), 2-factor authentication (2FA), and strong password policies on OKTA, GitHub, Google, AWS, and Estateably to ensure access to cloud services is protected.
What encryption is used?
All data sent to or from Estateably is encrypted in transit using 256 bit encryption. We also encrypt data at rest using an industry-standard AES-256 encryption algorithm.
What is Estateably's Security Incident Response?
In case of a system alert, events are escalated to Estateably’s teams providing Operations, Network Engineering, and Security coverage. Employees are trained on security incident response processes, including communication channels and escalation paths.
