Security Policy

Last Updated: October 1, 2026

Stream.Estate (operated by DLL SAS) takes technical and organisational measures to protect the confidentiality, integrity and availability of its API, its data and the information of its customers. This page describes the controls that are in place and the commitments we make to customers. It is referenced by, and incorporated into, the API License Agreement.

1. Hosting and infrastructure

  • The main API (api.stream.estate) is hosted on servers in Germany.
  • The website, the developer console and the V2 API are served through Cloudflare's DDoS-protected network.

2. Encryption

  • In transit: all communication with our services is encrypted with TLS; the main API (api.stream.estate) only accepts TLS 1.2 or higher.
  • Customer API keys: the full key is shown to the customer only once, at creation time; afterwards the dashboard and the API never display it in full.

3. Customer authentication

  • Customer authentication uses revocable API keys.

4. Availability monitoring

  • API availability is monitored continuously, and its status and incidents are published on our status page.

5. Software development lifecycle

  • API code is version-controlled, and changes run through automated CI checks; merge requests can only be merged once those checks pass.

6. Incident response

In the event of a security incident affecting customer data, Stream.Estate notifies the affected customer(s) without undue delay and, where the incident is material, no later than seventy-two (72) hours after becoming aware of it. The notification describes:

  • the nature and scope of the incident;
  • the categories of data potentially affected;
  • the measures already taken or planned to contain and remediate the incident;
  • the contact point for further information.

7. Data location and transfers

Customer operational data is stored in the European Union. Where any service involves a transfer of personal data outside the European Economic Area, Stream.Estate relies on the European Commission Standard Contractual Clauses or another lawful transfer mechanism, complemented by supplementary measures where required.

8. Compliance and certifications

Certifications, attestations or audit reports that are obtained will be referenced here once available. Customers under NDA may request the current state of the security programme by writing to [email protected].

9. Reporting a security issue

If you believe you have identified a vulnerability or security issue affecting Stream.Estate, please report it to [email protected] with sufficient detail for us to reproduce and triage the issue. We commit to:

  • acknowledge receipt within five (5) business days;
  • keep you informed of progress;
  • refrain from initiating legal action against researchers acting in good faith and respecting reasonable disclosure principles.

10. Updates to this policy

This security policy evolves alongside our infrastructure and our threat model. Changes are published on this page, with the date shown under “Last Updated”; we are not required to notify customers individually of a change. Customers with specific security requirements (for example detailed technical and organisational measures schedules) can request a dedicated security addendum to their contract.