Security Overview

Last Updated: August 7, 2026

CST Group Inc., doing business as Holy Estimate ("Holy Estimate," "we," "us," or "our"), takes the security of Customer Data seriously. This Security Overview describes the key practices and infrastructure we rely on to protect data submitted to holyestimate.com and the Holy Estimate estimating software (collectively, the "Services"). It is intended for general information; if your organization needs more detail as part of a vendor security review, contact us using the information in Section 9.

1. Hosting and Infrastructure

The Services are hosted on infrastructure provided by Vercel Inc., a hosting and application platform provider. Vercel maintains a SOC 2 Type 2 attestation covering security, confidentiality, and availability, and is ISO 27001:2022 certified. Vercel encrypts data at rest using 256-bit AES encryption and encrypts data in transit using HTTPS/TLS. Vercel also performs automated backups of underlying infrastructure and operates a global network designed for resilience against regional outages.

2. Encryption

All traffic to and from holyestimate.com and the Services is encrypted in transit using HTTPS/TLS. Data at rest is protected using the encryption capabilities of our hosting and database infrastructure.

3. Payment Security

Subscription payments are processed by Stripe, Inc., which is certified as a PCI Service Provider Level 1 — the highest level of certification in the payments industry — and is audited annually under SOC 1 and SOC 2 Type II compliance programs. Card numbers are encrypted and tokenized by Stripe; Holy Estimate does not store full payment card numbers on our own systems.

4. Access Controls

Access to Customer Data within our systems is limited to personnel who need it to operate, maintain, or support the Services. Access is granted on a least-privilege basis, tied to individual accounts, and revoked when no longer needed.

5. Application Security

We follow secure software development practices, including code review before changes are deployed and regular updates of the software components and dependencies the Services rely on. Security-relevant issues are prioritized for prompt remediation.

6. Monitoring

We monitor our systems for signs of suspicious or unauthorized activity and rely on the monitoring and alerting capabilities built into our hosting infrastructure.

7. Backups and Continuity

Customer Data benefits from the automated backup and disaster-recovery capabilities of our hosting infrastructure, which is designed to support recovery in the event of hardware failure or a regional outage.

8. Incident Response

If we confirm a security incident affecting Customer Data, we will investigate promptly and notify affected customers in accordance with our Data Processing Agreement and applicable law.

9. Reporting a Security Concern

If you believe you have discovered a security vulnerability affecting Holy Estimate, please contact us so we can investigate:

CST Group Inc., d/b/a Holy Estimate
Email: support@cstsupport.com
Phone: 518-483-4100 (NY) | 941-249-3520 (FL) | Toll-Free: 877-954-4100

Please provide enough detail for us to reproduce the issue, and avoid accessing or modifying data that does not belong to you while reporting a concern.

10. Changes to This Overview

We may update this Security Overview from time to time as our practices and infrastructure evolve. We will update the "Last Updated" date above when we do.