Trust center
Where your data lives, how it is kept apart from every other brokerage, who at SourceDeck can see it, how it is backed up, how you take it with you, and every company that touches it. Plain facts, checked against the code that runs the platform. If something is not on this page, ask and you will get a straight answer.
Uptime
The platform is checked from outside every hour. The live numbers, every incident in the last 90 days and our support response times are on the status page, computed from those checks rather than typed in.
- Website (sourcedeck.ai)Operational · 100% over 30 days
- SourceDeck appOperational · 100% over 30 days
- Background jobs (alerts, inbox sync, CASH tasks)Operational · 100% over 30 days
- CASH assistant toolsOperational · 100% over 30 days
- CASH voice lineOperational · 100% over 30 days
- Nightly backups and restore testOperational · 10.48% over 30 days
Where your data is stored
- Application servers: the SourceDeck app, the background jobs that run CASH and your alerts, and this website run on Fly.io in its Ashburn, Virginia region (iad).
- Database: your workspace data lives in a managed Postgres 16 database on Crunchy Bridge, hosted on AWS in us-east-1 (Northern Virginia).
- Files: photos, attachments and generated documents (offering memoranda, flyers, PDFs) are stored in Cloudflare R2 and served by long, unguessable links. Anyone holding one of those links can open that file, which is what lets you send a flyer to a client. Do not upload a document you would not be comfortable sharing by link.
- Backups: stored in a separate, private Cloudflare R2 bucket that is not served to the web.
Encryption
- Every SourceDeck site and the app force HTTPS. The app and sourcedeck.ai also send a two year HSTS header, so browsers refuse a plain HTTP connection.
- Connections from the app to the database require TLS.
- Credentials you connect for other services (email sending, mail, phone and similar keys) are encrypted by the application with AES-256-GCM before they are written to the database. The encryption key is kept outside the database.
- Customer sign-in is through Google, so SourceDeck holds no password for your account.
Your data is kept apart from every other brokerage
Every brokerage is its own tenant, and every table that holds brokerage data is protected by Postgres row level security, switched on and forced, so the rule applies even to the table owner. The rule is fail closed: a query that does not say which brokerage it is for gets no rows at all, rather than everyone’s. The application connects with a database role that cannot bypass row level security, so the separation is enforced by the database, not by a filter in our code.
Every table is classified (brokerage data, shared public records, or platform bookkeeping) in a register that a check on every proposed code change compares against the live database, so a new table cannot merge unclassified. A separate isolation test suite, which tries to read across brokerages on every tenant table, is run by hand against the live database.
Shared public records (parcels, MLS listings, corporate filings) are the one deliberate exception: they are public data, shared by every brokerage in a market, and never contain your contacts, deals or notes.
Who at SourceDeck can see your data
One person holds the platform administrator role today: the founder. That role can open a workspace to help with a support request. The start and the end of every such session are written to that workspace’s own audit log.
Support requests you send from inside the app are stored as tickets in your workspace; when CASH cannot answer one, it is escalated to the same administrator. Your own team sees what your workspace roles allow: the broker of record sees every seat, a team leader sees their team, and an agent sees their own work.
Backups
- The whole database is backed up every night at 3:15 am Eastern and copied to the private backup bucket.
- We keep the 14 most recent nightly backups, the 8 most recent Sunday backups and the 6 most recent first of the month backups.
- Every Sunday a restore test loads the latest backup into a scratch database and compares it against the live one. A backup older than 26 hours, or a restore test that failed or has not run in 8 days, pages us and shows on the status page.
- Backups and the restore test run from SourceDeck’s own operations machine, separate from the app servers.
Export and deletion
Your contacts, deals, listings and notes are yours. A workspace owner can download all of it at any time from Settings, Export your data: one zip with a CSV and a JSON file for each of contacts (with every email and phone on file), contact notes, deals and their history, listings and dictated property notes, plus a manifest of row counts. Every download is recorded in the workspace audit log.
To have a workspace deleted, download the export, then email [email protected] from the owner address. Deleted data then ages out of the backups on the schedule above.
AI and your data
CASH and the writing features send the text of the task they are doing (the email being drafted, the listing being described) to Anthropic’s Claude models through SourceDeck’s business API account. SourceDeck does not train or fine tune any model on your data, and your data is never used to answer another brokerage’s questions.
By default, nothing CASH writes reaches a third party on its own: outbound email, letters, texts and calls start as drafts that wait for a person to approve them. A workspace owner can choose to let a specific agent send without asking; that choice is per workspace and can be switched back at any time.
Subprocessors
Every company that may process your data, checked against the code. Public data sources the platform reads (US Census, the Federal Reserve, SEC filings, county records, the Florida corporate registry, MLS feeds) are not listed: they send data to us, not the other way round.
Used for every workspace
| Company | What for | What it may see |
|---|---|---|
| Fly.io | Runs the SourceDeck app, the background jobs and this website (Ashburn, Virginia region). | Everything the app processes, in memory while it runs. |
| Crunchy Data (Crunchy Bridge) | Managed Postgres database, on AWS us-east-1. | Your workspace data at rest. |
| Cloudflare | DNS and TLS in front of the sites, R2 file storage, and nightly database backups. | Files you upload, generated documents, backups, and web traffic passing through its network. |
| Anthropic | The Claude models behind CASH, drafting, classification and document writing. | The text of the task CASH is doing for you. |
| Resend | Sends email: alerts to you, and the outbound email you approve. | Recipient addresses and message content. |
| Sign-in, and Gmail, Analytics and Search Console when you connect them. | Your sign-in identity; mail and site analytics only if you connect them. | |
| Better Stack | Uptime monitoring heartbeat. | None of your data: it receives a ping with a pass or fail. |
Used only when you use the feature or connect the account
| Company | What for | What it may see |
|---|---|---|
| Stripe | Billing, once paid plans are switched on. | Billing contact and subscription details. |
| OpenAI | Transcribes voice notes and generates marketing images. | The audio or image prompt you submit. |
| ElevenLabs | The spoken voice of CASH. | The text CASH speaks aloud. |
| MillionVerifier and Bouncer | Checks that an email address can receive mail before anything is sent to it. | Email addresses. |
| Endato (EnformionGO) | Owner contact lookup (skip trace), only when paid lookups are switched on for your workspace. | An owner name and mailing address. |
| Apify | Public people and company lookups during contact enrichment. | A name and city or company. |
| SearchBug | Do Not Call list checks. | Phone numbers. |
| Twilio | Phone number lookups. | Phone numbers. |
| Quo (OpenPhone) | Business calling and call logging when connected. | Call records for the connected line. |
| Vapi | Voice calls to warm, consenting leads, when turned on. | The lead name, number and call script. |
| Lob | Printed direct mail you approve. | Recipient name, address and letter content. |
| Dropbox Sign | Electronic signatures on documents you send for signing. | The document and signer names and emails. |
| Cal.com | Booking links and scheduled calls. | Name, email and time of a booking. |
| Meta, LinkedIn and TikTok | Posts social content you approve to the accounts you connect. | The post text and images. |
| Runway | Generates short property videos when you ask for one. | Listing photos and a prompt. |
| Crexi | Listing integration when you connect a Crexi account. | Listing details and Crexi inquiry contacts. |
Security and data questions get direct answers: [email protected]. See also security and compliance and the privacy policy.
Put your market on her watch
SourceDeck onboards a small founding class, one market at a time. Founding rates lock for as long as you stay.