Trust & Security
Direct Offer Group LLC Trust Center
Who We Are
Direct Offer Group LLC is a private real estate investment and off-market deal network connecting property sellers, deal submitters, verified buyers, and funding partners.
Contact Information
Support Email: support@directoffergroup.com
Business Phone: (833) 756-5792
How The Network Works
- Buyers apply for access before receiving full deal access.
- Lenders and funding partners apply for access before receiving funding opportunities.
- Deal submitters can submit opportunities for Direct Offer Group LLC review.
- Direct Offer Group LLC reviews submissions before distributing buyer-facing deal information.
- Sensitive information is restricted based on user role, account status, approval status, and document visibility settings.
Data Protection
Direct Offer Group LLC uses practical security controls for a private real estate portal. These controls reduce risk, but no online system can be described as risk-free.
- HTTPS and HSTS headers are required for the production portal.
- Secure funding-room documents are encrypted at rest with AES-256-GCM using an environment-managed key.
- Private documents are decrypted only for authorized requests and streamed to the user instead of being written to public storage.
- Role-based access controls restrict buyer, lender, wholesaler, and admin routes and document downloads.
- Login sessions use HttpOnly, SameSite cookies with secure cookies enabled for HTTPS environments.
- Admin access requires authenticator-app two-factor authentication.
- Audit logs track sensitive account, login, deal, offer, document, approval, and security events.
- Uploaded deal and funding files are checked against allowed file types and scanned with ClamAV when accepted by upload routes.
- If the virus scanner is unavailable, protected upload routes reject the upload instead of saving it.
- Buyer, lender, and wholesaler approvals are reviewed through admin-controlled statuses and verification workflows.
- Private document access is controlled by stored visibility settings and backend authorization checks.