Anywhere Real Estate · Trust Center

Anywhere Real Estate Trust Center

Trust center

Anywhere Real Estate maintains a public trust center documenting SOC 1, SOC 2 Type 2, ISO/IEC 27001:2022, SOX, GDPR, EU-US Data Privacy Framework, and Cyber Essentials compliance.

Real EstateUnited StatesProperty ListingsMLSRESOBrokerageFranchisingPropTechTitleEscrowRelocationLeadsTransactions
Trust center: https://trust.anywhere.re/

Certifications & Compliance

SOC 1SOC 2 Type 2ISO/IEC 27001:2022SOXGDPREU-US Data Privacy FrameworkCyber Essentials

Source

Trust Center

anywhere-real-estate-trust-center.yml Raw ↑
generated: '2026-07-26'
method: searched
probe: true
source: https://trust.anywhere.re/
url: https://trust.anywhere.re/
platform: SafeBase
scope: >-
  IMPORTANT — this trust center is branded "Cartus Trust Center", not Anywhere Real Estate.
  Cartus is Anywhere's global relocation and talent-mobility business and the trust center is
  served on an anywhere.re subdomain, so it is genuinely first-party, but the certifications
  below are scoped to Cartus. Anywhere publishes no separate trust center covering the
  developer platform, the API gateway or the brokerage/franchise businesses.
scope_entity: Cartus (Anywhere Real Estate relocation business)
statement: >-
  Verbatim - "Welcome to Cartus' Trust Center. We prioritize Information Security, Data
  Privacy, and Compliance in every aspect of our operations. This Trust Center provides
  transparency into our security practices and offers a centralized resource for learning
  about our security posture."
certifications:
- SOC 1
- SOC 2 Type 2
- ISO/IEC 27001:2022
- SOX
- GDPR
- EU-US Data Privacy Framework
- Cyber Essentials
recent_update:
  title: 'Cartus Compliance Update: ISO/IEC 27001:2022 Certification Achieved'
  summary: >-
    Cartus announces achieving ISO/IEC 27001:2022 certification, described as covering its
    information security management system for global mobility data.
self_assessments:
- SIG Core
documents:
  access: NDA-gated request flow ("Get access"); "all materials shared under NDA are confidential and intended solely for internal evaluations"
  listed:
  - Data Flow Diagram (DFD)
  - SOC 2 Report
  - 'ISO/IEC 27001:2022 certificate'
  - SOC 2 Type 2 report
  - SIG Core self-assessment
  - Application Penetration Testing
  - Network Penetration Testing
  - Encryption Policy
  - Information Security Policy
  - Software Development Lifecycle Policy
  - Vulnerability Management Policy
  - Business Continuity Plan (BCP)
  - Disaster Recovery Plan (DRP)
  - Cartus Technical and Organizational Measures
control_areas:
- Product Security (Role-Based Access Control, SSO Support)
- App Security (Application Penetration Testing)
- Network Security (Network Penetration Testing)
- Incident Response (Incident Reporting Process)
- 'BC/DR (Business Continuity Plan, Disaster Recovery Plan, Tabletop Exercises, RTO, RPO, Data Center Risk Profile)'
- Corporate Security (Email Protection, Employee Training, Incident Response)
- Training (Training Program, Knowledge Base FAQ)
vulnerability_disclosure:
  public_program: false
  note: >-
    A Vulnerability Management Policy and an Incident Reporting Process are listed as
    NDA-gated documents, but there is no public vulnerability disclosure policy, no
    security.txt and no bug bounty program (HackerOne and Bugcrowd both probed, no Anywhere
    or Realogy program found). No VulnerabilityDisclosure or Security pointer is emitted.
evidence:
- source: https://trust.anywhere.re/
  status: 200
  date: '2026-07-26'
  keywords: [trust center, soc 2 type 2, soc 1, iso/iec 27001:2022, sox, gdpr, eu-us dpf, cyber essentials]
privacy_notice: https://privacy.anywhere.re/en/global-privacy-notice