Think about every tool your brokerage or proptech platform has added over the last five years. The CRM. The e-signature platform. The transaction management tool. The showing scheduler. The lead routing app. The automation someone set up to sync contacts between two systems.
Each one is a connection. Data moves through it. And most of them are still running, even if the person who set them up left the company.
What integrations actually do
When two systems are connected, they typically share data on an ongoing basis. A lead comes in through your website and gets pushed to your CRM. A transaction closes and triggers a notification to your accounting software. A client uploads documents to your portal and they get copied somewhere for processing.
The data moving through these connections is often the most sensitive data you hold: contact information, financial details, identity documents.
The problem with old integrations
Integrations get set up and then forgotten. Nobody watches them unless they break. But "not broken" and "safe" are not the same thing.
A connection built three years ago might be talking to a vendor that has since changed ownership, been acquired, or had their own security incident. The data you're sending them is still going there. You just don't know what's happening to it on the other end.
Access credentials drift too. The keys that allow one system to talk to another get shared between team members, copied into spreadsheets, passed around over email. They rarely get updated. A key created in 2021 that has never been changed is a long-lived risk that most teams aren't thinking about.
What a review looks like
Going through active integrations doesn't require deep technical knowledge. It requires someone sitting down and asking: what tools are connected, what data do they receive, who authorized it, and when was it last reviewed?
For most organizations, that list is longer than expected. And somewhere on it is usually at least one connection that nobody remembered was still running.