Comparison Overview

Doma

VS

Greystar

Doma

undefined, San Francisco, CA, undefined, US
Last Update: 2025-03-16 (UTC)
Between 900 and 1000

Excellent

Doma is making title and escrow a simpler, seamless process for lenders, agents and homebuyers across the country. We build transformative technology driven by our passion to improve the customer experience.

NAICS: None
NAICS Definition:
Employees: 2,121
Subsidiaries: 3
12-month incidents
0
Known data breaches
0
Attack type number
0

Greystar

465 Meeting St, Charleston, South Carolina, 29403, US
Last Update: 2025-05-06 (UTC)

Excellent

Between 900 and 1000

Founded in 1993, Greystar provides world-class service in the residential rental housing industry. Our innovative vertically integrated business model integrates the management, development and investment disciplines of the rental housing industry on international, regional and local levels. This unique approach and our commitment to hiring the best professionals have resulted in record growth, making us one of the most respected and trusted global real estate companies. Because our vertically integrated business model includes both investment and service-oriented businesses, weโ€™re able to maintain a constant presence in local markets and create value in all phases of the real estate cycle. Our international platform provides economies of scale, financial sophistication, institutional quality reporting and tremendous capital relationships, while our city offices provide local market expertise and execution. Supported by a global team of 20,000+ employees, Greystarโ€™s experienced and cross-functional executive team boasts on average over 23 years of industry experience and provides a diverse perspective throughout the investment process. Over the years, Greystar has learned whatโ€™s important to people when it comes to a place to call home. Thatโ€™s why we continually strive to provide beautiful living environments and innovative services that enhance the living experience. We take great pride in knowing that our homes are inviting places for residents to celebrate lifeโ€™s important moments. Privacy Policy: https://www.greystar.com/privacy DMCA: https://www.greystar.com/terms-of-use#Copyright%20Infringement%20Policy

NAICS: None
NAICS Definition: Others
Employees: 16,976
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/domahq.jpeg
Doma
โ€”
ISO 27001
Not verified
โ€”
SOC 2
Not verified
โ€”
GDPR
No public badge
โ€”
PCI DSS
No public badge
https://images.rankiteo.com/companyimages/greystar.jpeg
Greystar
โ€”
ISO 27001
Not verified
โ€”
SOC 2
Not verified
โ€”
GDPR
No public badge
โ€”
PCI DSS
No public badge
Compliance Summary
Doma
100%
Compliance Rate
0/4 Standards Verified
Greystar
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Real Estate Industry Average (This Year)

No incidents recorded for Doma in 2025.

Incidents vs Real Estate Industry Average (This Year)

No incidents recorded for Greystar in 2025.

Incident History โ€” Doma (X = Date, Y = Severity)

Doma cyber incidents detection timeline including parent company and subsidiaries

Incident History โ€” Greystar (X = Date, Y = Severity)

Greystar cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/domahq.jpeg
Doma
Incidents

No Incident

https://images.rankiteo.com/companyimages/greystar.jpeg
Greystar
Incidents

No Incident

FAQ

Both Doma company and Greystar company demonstrate a comparable AI risk posture, with strong governance and monitoring frameworks in place.

Historically, Greystar company has disclosed a higher number of cyber incidents compared to Doma company.

In the current year, Greystar company and Doma company have not reported any cyber incidents.

Neither Greystar company nor Doma company has reported experiencing a ransomware attack publicly.

Neither Greystar company nor Doma company has reported experiencing a data breach publicly.

Neither Greystar company nor Doma company has reported experiencing targeted cyberattacks publicly.

Neither Doma company nor Greystar company has reported experiencing or disclosing vulnerabilities publicly.

Doma company has more subsidiaries worldwide compared to Greystar company.

Greystar company employs more people globally than Doma company, reflecting its scale as a Real Estate.

Latest Global CVEs (Not Company-Specific)

Description

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A reflected cross-site scripting vulnerability has been identified in versions 2.2.1 and earlier. The vulnerability exists in the error handling mechanism of the login page, where malicious scripts embedded in server hostnames are executed in the victim's browser context without proper sanitization. This issue is fixed in version 2.2.2.

Risk Information
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Description

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A Denial of Dervice vulnerability has been identified in versions 2.2.1 and earlier. The vulnerability permits an unauthenticated actor to crash the application through the submission of specially crafted Unicode input, requiring no prior authentication or privileges. The flaw manifests when Unicode tag characters are submitted to the Server field on the login page. The application fails to properly handle these characters during the ASCII conversion process, resulting in an unhandled exception that terminates the application within four to five seconds of submission. This issue is fixed in version 2.2.2.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description

Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3.

Risk Information
cvss4
Base: 2.1
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The official Docker image for Termix versions 1.5.0 and below, due to being configured with an Nginx reverse proxy, causes the backend to retrieve the proxy's IP instead of the client's IP when using the req.ip method. This results in isLocalhost always returning True. Consequently, the /ssh/db/host/internal endpoint can be accessed directly without login or authentication. This endpoint records the system's stored SSH host information, including addresses, usernames, and passwords, posing an extremely high security risk. Users who use the official Termix docker image, build their own image using the official dockerfile, or utilize reverse proxy functionality will be affected by this vulnerability. This issue is fixed in version 1.6.0.

Risk Information
cvss4
Base: 9.2
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

OpenPLC_V3 has a vulnerability in the enipThread function that occurs due to the lack of a return value. This leads to a crash when the server loop ends and execution hits an illegal ud2 instruction. This issue can be triggered remotely without authentication by starting the same server multiple times or if the server exits unexpectedly. The vulnerability allows an attacker to cause a Denial of Service (DoS) against the PLC runtime, stopping any PC started remotely without authentication. This results in the PLC process crashing and halting all automation or control logic managed by OpenPLC.

Risk Information
cvss3
Base: 7.1
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
cvss4
Base: 6.1
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X