Trust & compliance

Sodar is designed toward SOC 2 and GDPR from day one — this page is the working summary; formal reports and DPAs are available on request.

Built to be trusted with listings

Compliance isn’t an afterthought.

Camera permission, explicit

Sodar asks for the device camera only when you start a scan and uses it only for that capture.

AI disclosure

Every published walkthrough carries a clear, visible label that it is an AI-processed reconstruction.

Security

Built toward SOC 2 and GDPR from day one — encrypted storage, scoped CRM credentials, audit logs per property.

Broker data ownership

Captures, walkthroughs and engagement data belong to the broker. Disconnecting Sodar exports everything.

In detail

How data actually moves.

Camera access

The device camera is requested only when a scan starts, with explicit permission, and used only for that capture.

Storage

Captures and rendered walkthroughs are encrypted at rest and in transit; access is scoped per broker account.

AI disclosure

Every public walkthrough carries a visible label identifying it as an AI-processed reconstruction.

Data retention

Captures and walkthroughs are retained for the life of the listing plus a fixed grace period, then purged on request.

Access control

CRM credentials and API keys are scoped to the minimum permissions the integration needs.

Sub-processors

Third-party processing and payment providers are listed in the Data Processing addendum.

See also: Privacy Policy, Data Processing Addendum.

Questions for security review

Need a security questionnaire answered?

Reach out and we’ll return a completed questionnaire or SOC 2 status directly.

Contact security