Trust & Security

This page is maintained by the Acquilink team to answer common security and privacy questions. It describes our current practices and the platform controls we rely on.

Access & Authentication

Acquilink supports email-and-password authentication, with optional Google OAuth sign-in. All authentication is handled through a managed identity provider with session tokens, refresh rotation, and multi-factor authentication (MFA) support.

Role-based access control enforces that users can only view and edit records within their own brokerage tenant. Internal brokerage staff, referral partners, buyers, sellers, and other deal participants each see only the data their role permits.

Data Encryption

Data is encrypted in transit using TLS 1.2+ and encrypted at rest by the underlying cloud database and storage providers. File uploads to data rooms and attachments are stored in encrypted object storage with access controlled by per-user, per-record permissions.

Subprocessors & Integrations

Acquilink uses the following subprocessors to deliver the service:

  • Supabase — database, authentication, realtime, and storage infrastructure.
  • Stripe — payment processing and subscription billing.
  • DocuSign — electronic signatures and document execution (optional, broker-configured).
  • Resend — transactional and campaign email delivery.

Each integration is configured with the minimum required permissions. Stripe customer and subscription identifiers are restricted to server-side access and are not exposed to the client application.

Data Collection & Use

We collect only the information necessary to operate the brokerage platform: contact details for buyers, sellers, agents, and referral partners; deal and listing data; and usage data for billing and support.

We do not sell personal data. Data is used solely to provide the Acquilink service and to communicate with users about their accounts and transactions.

Retention & Deletion

Records are retained for as long as the tenant account is active and as required for legal or regulatory obligations. When a tenant account is closed, data is queued for deletion in accordance with our data retention schedule.

Individual records (contacts, listings, transactions) can be deleted by authorized brokerage staff within the application.

Security Contact

If you discover a security issue or have a privacy question, please reach out to us at security@acquilink.com.

We do not operate a formal bug bounty program, but we welcome responsible disclosure and will acknowledge reports promptly.

This page reflects our practices as of the date shown and may be updated from time to time. It is not a legal contract, certification, or independent audit report.