Last Updated: October 1, 2026
Stream.Estate (operated by DLL SAS) takes technical and organisational measures to protect the confidentiality, integrity and availability of its API, its data and the information of its customers. This page describes the controls that are in place and the commitments we make to customers. It is referenced by, and incorporated into, the API License Agreement.
In the event of a security incident affecting customer data, Stream.Estate notifies the affected customer(s) without undue delay and, where the incident is material, no later than seventy-two (72) hours after becoming aware of it. The notification describes:
Customer operational data is stored in the European Union. Where any service involves a transfer of personal data outside the European Economic Area, Stream.Estate relies on the European Commission Standard Contractual Clauses or another lawful transfer mechanism, complemented by supplementary measures where required.
Certifications, attestations or audit reports that are obtained will be referenced here once available. Customers under NDA may request the current state of the security programme by writing to [email protected].
If you believe you have identified a vulnerability or security issue affecting Stream.Estate, please report it to [email protected] with sufficient detail for us to reproduce and triage the issue. We commit to:
This security policy evolves alongside our infrastructure and our threat model. Changes are published on this page, with the date shown under “Last Updated”; we are not required to notify customers individually of a change. Customers with specific security requirements (for example detailed technical and organisational measures schedules) can request a dedicated security addendum to their contract.