Industry

Proptech: Transaction and Identity Data on the Move

March 19, 2026 Alexandre Genest 6 min

Your most valuable data leaves on access you granted on purpose. Proptech platforms move transaction, identity, and financial data across parties on sanctioned access. Where the permitted-pattern blind spot opens in real-estate tech.

Proptech: Transaction and Identity Data on the Move cover image

One mortgage closing puts a buyer's bank statements, pay stubs, Social Security number, wiring instructions, and title records into motion across the buyer, the agent, the lender, the title company, the escrow officer, and three or four integrated partners. Every hop runs on access your platform granted on purpose. The lender's API key is a real credential. The CRM sync account is one you provisioned. The closing tool reads escrow instructions because you wired it to.

So the data a person hands over once in a lifetime does not leak through a door someone forgot to lock. It leaves through the doors you built.

Permission is not the same as correct

Most proptech security spend keeps unauthorized parties out: SSO, encryption at rest, vendor reviews, SOC 2. That work is aimed at the wrong threat. The records that matter most are already reachable by parties you authorized, and every move they make is permitted, so every tool you own correctly lets it through.

The danger is the pattern across moves. The same lending key reading ten times its normal volume. The identity-verification service pulling records for transactions it is not party to. The export job that fires at 2am Sunday instead of inside the nightly window. Permission tells you a move was allowed. It does not tell you the move was right. That gap is the structural problem in proptech, and it sits exactly where your stack stops looking.

The layers you already run do not watch the move

Wiz and the CSPM category prove the S3 bucket holding wiring instructions is encrypted, private, configured right. That is a fact about the bucket's state. It says nothing about the read against the bucket, by this identity, at this hour.

CrowdStrike and the EDR category catch malware on the laptops your agents and ops staff use. The partner integration pulling identity documents is not on a laptop and is not malware. It is an API call you sanctioned.

SIEM and your application logs record that the call happened. They show you, days later, that the lending key read 4,000 borrower files last Thursday. By then the data is at the destination. The log is the disclosure letter with a timestamp on it.

None of these tools is broken. Each does its job. The threat that slips between them uses sanctioned access in an abnormal shape, and no layer there was built to score the shape of the movement itself.

Hilt watches the movement, not the door

Hilt is runtime Data Movement Governance. One lightweight collector watches data movement at the kernel, metadata only by default, off the path, single-tenant in your own cloud. It never sits between your data and where it is going, and it does not read the closing disclosure to govern how the closing disclosure moves.

The default vantage is metadata: which identity, which job, which destination, what volume, what timing. Content-aware inspection is there when you want it, never the price of admission. For a platform holding financial and identity records under real regulatory exposure, that line holds. You see that a pattern is wrong without anyone reading a borrower's bank statement to prove it.

Every move resolves to a probabilistic identity and the job behind it. When the income-verification integration starts pulling borrower documents for transactions it was never assigned, no single fact convicts it. The identity is reading paths outside its scope. The volume runs high against months of history. The destination is one this job has never written to. Each signal alone is noise. Stacked, they are a case with the user, the job, and the destination already written into it, not an alert for someone to triage.

When the pattern crosses the line, Hilt isolates the host at the network from the control plane. It does not filter packets inline and does not stand in the path of a closing. The host goes quiet, the move stops, and the events never leave your account. Overhead is checkable, not a slogan: on the order of 0.1% of one core and 4 to 8 MB of memory per host. On a platform where a closing cannot stall and an integration cannot time out, a collector that watches from beside the path is the only posture that fits.

Where it stops

Hilt can stand in for your endpoint sensor, and many proptech teams retire their EDR once it is in place; keep one alongside only if you also want the malware-and-intrusion layer. Hilt does not replace your CSPM or your access management. Keep the bucket configured right. Keep handing partners least-privilege credentials. Those controls shrink the surface. None of them was built to ask whether a permitted move, by an authorized party, fits how your transaction data normally flows. That is the question Hilt answers, sitting behind the permission check, on the movement, surfacing the move that was allowed but wrong.

Run one test against your current stack. Pick a partner credential and ask what its data movement looked like last week, resolved to the job behind it and scored against how it normally moves. If you cannot answer for a single transaction, that is the gap. Thirty minutes, engineer to engineer, is enough to see whether it is yours.