Legal

Security

Effective date: September 13, 2026

See also our Terms and Conditions and Privacy Policy.

1. What this page is

This page describes the security practices Brokrly (Nestly Inc.) actually has in place today, in plain terms. As an early-stage company, this will change — we’ll update this page as our practices grow, rather than promise a roadmap item as if it were already built.

For questions about a specific integration, a security questionnaire, or a more detailed document (architecture, sub-processor list, or similar), contact us at info@brokrly.com.

2. Encryption

All traffic to and from Brokrly’s website and web application is encrypted in transit (HTTPS/TLS). Passwords are never stored in plain text — they’re hashed using bcrypt, an industry-standard algorithm, before being stored.

3. Access controls

Access to a brokerage’s data within Brokrly is scoped to that brokerage’s own workspace and its authorized users. Administrators control who on their team has access, including removing a departing agent’s access at any time. Internal access to customer data is limited to what’s needed to operate and support the Service.

4. Human approval before AI-driven actions

Brokrly’s AI features can draft communications and propose actions, but actions with a real external effect — sending a message, updating a record — go through an explicit draft-review-confirm step rather than executing automatically and unsupervised. We treat this as a security control, not just a product convenience: it’s a deliberate checkpoint between an AI-generated suggestion and anything actually happening in the world.

5. AI processing and data handling

Details on which AI providers process customer data, where, and under what restrictions are covered in our Privacy Policy, sections 3 and 4 — including our Google API Limited Use commitments and the restrictions on how Customer Content can and can’t be used to improve models. We don’t duplicate those details here to avoid the two documents drifting out of sync; treat the Privacy Policy as the source of truth on AI data handling specifically.

6. Where we are today, honestly

Brokrly does not currently hold a formal third-party security certification (such as SOC 2 or ISO 27001). We’re an early-stage company and are building toward that as we grow, rather than claiming it before it’s true. If you need more detail than this page provides to evaluate Brokrly for your own use — an architecture overview, a completed security questionnaire, or similar — reach out and we’ll work with you directly.

7. Reporting a security concern

If you believe you’ve found a security vulnerability or suspect unauthorized access to your account, contact us immediately at info@brokrly.com. We’ll acknowledge and investigate reports in good faith.

8. Changes to this page

We’ll update the effective date above whenever this page materially changes, consistent with how we handle updates to our Terms and Privacy Policy.

Nestly Inc., 425 Virginia Street, STE b, Vallejo, CA 94590, United States.

Connection