Legal
Security practices
How we protect listing, lead, and client data, and how to report an issue.
Last updated August 25, 2026
Access control
The portal is staff-only: there are no public consumer accounts. Administrators and agents hold distinct roles, and agents see only the listings and pipeline records assigned to them.
Transport and headers
All traffic is served over HTTPS with HSTS. This site sends a restrictive Content Security Policy, denies framing, and disables MIME-type sniffing.
Tenant isolation
Each tenant's listings, leads, and client records are scoped to their own account. A tenant cannot read another tenant's data.
Reporting a vulnerability
Email hello@nxtclose.com with steps to reproduce. Please give us a reasonable window to fix an issue before disclosing it publicly. We do not pursue legal action against good-faith research.
Questions about this policy? Email hello@nxtclose.com.