Information Security Policy
Last updated: 3 August 2026
Security is built into EstateRadar, not added on top. This policy explains the technical and organisational measures we use to protect the platform and the information it processes. It is written in plain language and describes controls that are actually in place; it is reviewed as the platform evolves.
1. Scope
This policy covers the EstateRadar websites, APIs and background services, and the data they process — property listings, media, analytics and the limited personal data of visitors, owners, agents and developers who use the platform.
2. Encryption in transit
All traffic between your browser and EstateRadar is served over HTTPS using modern TLS. Requests to our origin infrastructure are likewise encrypted. We do not serve the platform over unencrypted connections.
3. Access control and least privilege
Administrative and data-store access is restricted to the smallest set of people and services that need it, authenticated with strong credentials and secrets that are never committed to source control. Application secrets are held in the hosting provider’s protected environment, not in the codebase.
4. Application and abuse protection
Public endpoints — in particular the AI search — are protected by rate limiting, per-identity request quotas, automated anomaly detection that temporarily blocks abusive clients, and an input firewall that screens for injection and malicious patterns before requests are processed. Sensitive requests are additionally shielded at the network edge.
5. Data minimisation
We collect as little personal data as possible. Most browsing relies on an anonymous device identifier rather than an account, and we do not sell personal data. Where we do process personal data, we do so for the purposes described in our Privacy Policy.
6. Media and metadata
Uploaded and proxied images are re-encoded server-side, which strips embedded metadata (such as EXIF and location tags) before they are served. Original source URLs and supplier filenames are never exposed to the browser.
7. Hosting and infrastructure
EstateRadar runs on established cloud providers with their own physical, network and platform security controls, using managed, access-restricted databases. We keep our platform and dependencies up to date.
8. Third-party processors
We use a small number of reputable service providers (for hosting, database, AI processing, maps and email). They process data only on our instructions and under their own security and data-protection commitments.
9. Monitoring and incident response
We log security-relevant events and monitor for abuse and errors. If we become aware of a security incident that affects personal data, we will act to contain it and notify affected users and the relevant authority where the law requires.
10. Reporting a vulnerability
If you believe you have found a security issue, please tell us at our contact form. We welcome responsible disclosure and ask that you give us reasonable time to investigate and fix an issue before making it public.
11. Your rights
Your rights over your personal data, including access and erasure, are set out in our GDPR and Privacy Policy pages.