Security
Status: 5 September 2026
Confidential documents pass through OFFMARKET24: exposés, rent rolls, purchase price and owner details. On this page we summarise how we protect that data and how you can report security issues to us.
How we protect your data
- Location of the data: the database, uploaded files, the associated email accounts and all backups are located exclusively in data centres in Germany (Hetzner Online GmbH, Falkenstein). No processing of this content takes place outside Germany.
- Encryption: transmission takes place exclusively via SSL/TLS. Backups are stored in encrypted form.
- Access restriction: access to property documents is granted exclusively to authorised employees and – strictly bound by instructions on the basis of a data processing agreement – to our hosting service provider.
- Staged disclosure: investors initially receive only anonymised short profiles without address, owner details or identifying photos. Complete documents are transmitted only after express release by the provider.
- Protection of the forms: all public forms are protected against automated misuse by CSRF tokens, timestamp checks, honeypot fields, rate limiting and Cloudflare Turnstile.
- Logging: failed login attempts and indications of attempted attacks are logged and evaluated. Details of the processing are set out in our privacy policy.
Reporting security vulnerabilities
We welcome reports from security researchers. If you discover a vulnerability in our systems, please report it to [email protected] with the subject "Security".
Helpful for us are:
- a description of the vulnerability and the affected component or URL
- steps that allow the issue to be reproduced
- an assessment of the possible impact
- your contact details for follow-up questions
Our commitments
- We confirm receipt of your report within 48 hours on business days.
- We keep you informed about the status and let you know as soon as the vulnerability has been fixed.
- We will not take legal action against persons who observe the rules below and report a vulnerability to us responsibly.
- On request we will name you as the finder once the issue has been resolved.
Rules for security testing
- Do not access third-party data, do not alter or delete data and do not disrupt services. Stop your test as soon as you have established that a vulnerability exists.
- Do not carry out load tests, denial-of-service attacks or automated mass scanning.
- Do not use social engineering against our employees or customers.
- Give us a reasonable period to fix the issue before you publish any details.
Not relevant for us
As a rule we cannot process reports about missing best-practice headers without demonstrable exploitability, about the results of pure scanner runs without proof of exploitability, or about third-party services that we do not operate.
Suspected fraud rather than a security vulnerability?
If you would like to report a fraudulent offer, a fake identity or a phishing email, please use the page Report fraud and abuse.