Security Overview
Last Updated: August 7, 2026
CST Group Inc., doing business as Holy Estimate ("Holy Estimate," "we," "us," or "our"), takes the security of Customer Data seriously. This Security Overview describes the key practices and infrastructure we rely on to protect data submitted to holyestimate.com and the Holy Estimate estimating software (collectively, the "Services"). It is intended for general information; if your organization needs more detail as part of a vendor security review, contact us using the information in Section 9.
1. Hosting and Infrastructure
The Services are hosted on infrastructure provided by Vercel Inc., a hosting and application platform provider. Vercel maintains a SOC 2 Type 2 attestation covering security, confidentiality, and availability, and is ISO 27001:2022 certified. Vercel encrypts data at rest using 256-bit AES encryption and encrypts data in transit using HTTPS/TLS. Vercel also performs automated backups of underlying infrastructure and operates a global network designed for resilience against regional outages.
2. Encryption
All traffic to and from holyestimate.com and the Services is encrypted in transit using HTTPS/TLS. Data at rest is protected using the encryption capabilities of our hosting and database infrastructure.
3. Payment Security
Subscription payments are processed by Stripe, Inc., which is certified as a PCI Service Provider Level 1 — the highest level of certification in the payments industry — and is audited annually under SOC 1 and SOC 2 Type II compliance programs. Card numbers are encrypted and tokenized by Stripe; Holy Estimate does not store full payment card numbers on our own systems.
4. Access Controls
Access to Customer Data within our systems is limited to personnel who need it to operate, maintain, or support the Services. Access is granted on a least-privilege basis, tied to individual accounts, and revoked when no longer needed.
5. Application Security
We follow secure software development practices, including code review before changes are deployed and regular updates of the software components and dependencies the Services rely on. Security-relevant issues are prioritized for prompt remediation.
6. Monitoring
We monitor our systems for signs of suspicious or unauthorized activity and rely on the monitoring and alerting capabilities built into our hosting infrastructure.
7. Backups and Continuity
Customer Data benefits from the automated backup and disaster-recovery capabilities of our hosting infrastructure, which is designed to support recovery in the event of hardware failure or a regional outage.
8. Incident Response
If we confirm a security incident affecting Customer Data, we will investigate promptly and notify affected customers in accordance with our Data Processing Agreement and applicable law.
9. Reporting a Security Concern
If you believe you have discovered a security vulnerability affecting Holy Estimate, please contact us so we can investigate:
CST Group Inc., d/b/a Holy Estimate
Email: support@cstsupport.com
Phone: 518-483-4100 (NY) | 941-249-3520 (FL) | Toll-Free: 877-954-4100
Please provide enough detail for us to reproduce the issue, and avoid accessing or modifying data that does not belong to you while reporting a concern.
10. Changes to This Overview
We may update this Security Overview from time to time as our practices and infrastructure evolve. We will update the "Last Updated" date above when we do.