
Data security and trustworthy sources: Urbital's lesson for PR proptech
An automated valuation is only as good as its data. What the FTC Safeguards Rule requires, and why data provenance matters as much as encryption.
An automated valuation model (AVM) like the one Urbital runs in Puerto Rico is only as good as the data feeding it. The moment that number — an estimated property price — enters a mortgage bank's or a broker's decision, it stops being "just an app" and becomes an input into a real financial decision.
That carries concrete legal obligations, not just good intentions. The FTC's Safeguards Rule (under Gramm-Leach-Bliley) no longer applies only to banks: since the 2023 amendments it explicitly covers "finders" — companies that bring together buyers and sellers or facilitate financing — plus appraisers and other nonbank entities that handle customers' nonpublic information. That means a written information security program, encryption, MFA, and penetration testing at minimum. Since May 2024, covered entities must also notify the FTC within 30 days if an incident affects 500 or more consumers (see the official FTC guidance and the notification requirement notice).
There is a second layer that gets forgotten: where the data comes from, not just how it is protected. An AVM fed by unverified listings or unaudited scraping produces systematically different valuations than one built on trustworthy sources — in Puerto Rico that means actual sale records, CRIM as the property-tax assessment source, and verifiable comparables, not just whatever is posted in a listing. When Urbital Pro's output lands in a bank's underwriting file, an inflated or poorly-cleaned comp set is not a UI bug — it is underwriting risk someone pays for later.
In practice this means concrete, checkable controls, not a PDF policy nobody reads: encryption in transit and at rest for property and user data, role-segmented access (consumer, broker, and bank tiers should not see or audit the same things), an audit log of who pulled which valuation and when, and a clear contractual relationship with every upstream data source about freshness and accuracy — "we got it off the internet" is not a data-sourcing policy.
Worth dismantling a common myth too: that "aggregated" or "public" data carries no privacy obligation. A property profile combining address, sale history, assessment, and one specific user's search pattern can re-identify a person even though each individual data point looks harmless alone — the same principle that applies to any data broker, not just real estate platforms.
For a Puerto Rico proptech serving both consumers and mortgage banks and brokers through Urbital Pro, treating data security and source reliability as two separate concerns is exactly how an AVM loses credibility with a bank underwriter. Treating them as one program — verified sources feeding a pipeline that actually meets GLBA — is what turns an automated valuation into something a loan officer can actually rely on.

Writes about practical cybersecurity for SMBs in Puerto Rico and the Caribbean — no fluff, just what actually needs to get done.


