Security and compliance
Last updated: August 18, 2026
Realtors trust DeedRead with pre-offer documents that are sensitive by nature: depreciation reports, strata minutes, title searches. This page explains, in plain language, how the product is built to protect them.
Your documents never leave your browser
This is the core of our security model, and it is architectural, not a promise. Documents you upload are read on your own device: your browser extracts the text needed for analysis, and only that text is sent to our servers. The original files are never uploaded, and we keep no server-side store of documents or generated reports. What we never hold, we can never lose.
Encryption in transit
All traffic to deedread.ca is encrypted with TLS (HTTPS), and we instruct browsers to refuse unencrypted connections to us (HTTP Strict Transport Security). Extracted text sent for analysis travels over the same encrypted channel and is processed transiently.
Sign-in without passwords
DeedRead accounts use Google sign-in or email magic links. There is no DeedRead password to guess, leak, or reuse. Account data lives in a database where each user's rows are isolated by row-level security, so one account can never read another's data.
Payments handled by Stripe
Card details go directly to Stripe, a PCI-DSS certified payment processor. Your card number never touches DeedRead's servers.
Hardened by default
- Every page is served with modern browser security headers (content-type protections, frame-embedding blocked so reports cannot be displayed inside another site, restrictive referrer and permissions policies).
- Server-side requests triggered by user input are strictly validated so they can only reach the public web.
- AI-generated report content passes through a validation layer before it reaches your screen.
- Error messages shown in the product never expose internal system details.
Vendors we rely on
DeedRead runs on a small set of established providers: Vercel (hosting), Supabase (accounts database), Stripe (payments), and Anthropic (AI analysis). Each maintains independent security audits (SOC 2). As disclosed in our Privacy Policy, extracted document text is processed by Anthropic on servers in the United States.
Working toward certification
We are aligning DeedRead with the Canadian Centre for Cyber Security's baseline controls for small and medium organizations, the standard behind the federal CyberSecure Canada certification, and intend to pursue certification. This page will be updated as that progresses.
DeedRead for managing brokers
Managing brokers are now expected to set the rules for how their agents use AI. This section is for the broker or agent evaluating DeedRead against those obligations. It explains, in plain language, how the way DeedRead is built lines up with the AI guidance issued for real estate in British Columbia and nationally. It is informational, not legal advice: your brokerage remains responsible for its own policies and for meeting its regulatory and insurance obligations.
What the guidance asks for
BCFSA's guidance on artificial intelligence, CREA's AI principles, and the guidance from BC's errors-and-omissions insurer converge on the same three expectations for using an AI tool with client information:
- Consent and data handling. Get the client's consent before putting their information into an AI tool, and handle that information responsibly.
- Verification. Do not rely on AI output blindly; check it before you act on it.
- Human accountability. The licensee stays responsible for the advice given to the client. AI assists; it does not decide.
DeedRead is built around all three.
Consent and confidentiality, reduced by design
DeedRead's privacy model is architectural, not a promise. Uploaded documents are parsed to text inside the agent's browser. The original files never upload to our servers, and we keep no server-side store of documents or reports. Only the extracted text needed for the one analysis is sent, over an encrypted connection, and it is processed transiently rather than stored. Because the source documents never leave the agent's device, there is materially less client information exposed to any third party in the first place, which is exactly the risk the consent expectation is meant to manage. The sections above and our Privacy Policy set out the details.
Verification, with a page citation on every finding
Every figure and flag in a DeedRead report is cited to the source page it came from. That is deliberate: it lets the agent spot-check any finding against the underlying document in seconds and stay the expert in the room. The report is a first read that invites verification, not a black box that asks for trust. A public sample report shows the page-numbered flags.
Human accountability: a screening aid, not advice
DeedRead is positioned as a pre-offer screening aid. It surfaces what to verify and who to ask; it does not give legal, financial, appraisal, or inspection advice, and it does not replace a professional review. The agent and the client's professionals make the decisions. Report copy carries this framing so the client understands it too.
Fitting DeedRead into a brokerage AI policy
Because DeedRead stores no documents and no reports on its servers, the data-handling section of a brokerage AI policy is short to write: source documents stay on the agent's device, only extracted text is processed for a single analysis, and nothing is retained. If it helps your review, we can provide a managing-broker information packet that maps DeedRead's data flow and screening-aid framing to the points the guidance raises. Email info@deedread.ca and we will send it.
Pre-offer screening and E&O exposure
The moment DeedRead serves is the pre-offer read, before a client removes subjects or writes without them. That is also where a great deal of errors-and-omissions exposure sits. A fast, page-cited first read helps an agent raise the right questions inside a short decision window, while still recommending a professional review of the documents before the client commits. It is a way to be more thorough at the pre-offer stage, not a substitute for the human review a specific deal warrants.
Talk to us
Questions from a compliance or managing-broker perspective are welcome. Email info@deedread.ca and a founder will respond. You can also try the tool on your own current listing: the first 10 reports are free at deedread.ca/login.
Found a security issue?
We welcome good-faith security research. Email info@deedread.ca with the subject "Security report" and we will acknowledge within 3 business days. A machine-readable policy is published at /.well-known/security.txt. We will not pursue legal action for responsible, non-destructive research reported to us privately.