Legal
Security
Last updated September 1, 2026
How we protect your data, your tenants' data and the money that moves through Rentier. Report anything to [email protected] and we will reply to every message.
1. Our commitment
Security is how the product is built, not a layer added afterwards. We work to defense in depth, least privilege and continuous monitoring, and we align our controls with SOC 2, ISO 27001 and the NIST Cybersecurity Framework.
Security is owned across the company rather than by one team, and our program is reviewed by the executive team on a regular cadence.
2. Data protection
All data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Documents and photos are stored in private object storage and served through short-lived signed links.
Backups are encrypted, run daily and support point-in-time recovery. Production data is never used in development.
3. Access controls
Two-factor authentication is available on every account and can be required for a whole organization. Sessions time out and tokens rotate.
Inside Rentier, access follows least privilege. Staff access to customer data is logged, reviewed quarterly and removed the day a role changes.
4. Infrastructure
Rentier runs in SOC 2 compliant cloud data centers with network isolation between environments. Deploys are health-gated and rolled back automatically on failure.
Administrative access to infrastructure requires a VPN and a second factor, and every change to production is recorded.
5. Vulnerability management
Production systems and dependencies are scanned continuously, and an independent firm runs a penetration test at least once a year.
Critical findings are triaged and fixed within 24 hours, high-severity findings within 72 hours. Patches ship through the same health-gated pipeline as everything else.
6. Third-party security
Payments go through Stripe (PCI DSS Level 1). Bank connections use Plaid; Rentier never sees your bank credentials. Every vendor with access to customer data is reviewed before integration and annually after.
Vendor contracts carry data protection terms, breach notification duties and a right to audit, and vendor access is limited to what the integration needs.
7. Incident response
Monitoring and automated alerting surface suspicious activity in real time. Affected systems are isolated first, then investigated, fixed and verified before normal operation resumes.
Customers affected by a confirmed breach are notified within 72 hours, with regulators notified where the law requires it. Every incident gets a written review and tracked follow-up actions.
8. Responsible disclosure
If you find a vulnerability, email [email protected] with the details and steps to reproduce. We acknowledge every report within 24 hours and will keep you updated until it is closed.
We ask only that you give us reasonable time to fix an issue before you make it public, and that you avoid accessing other people’s data while testing.
9. Employee security
Everyone who works here clears a background check before they are given access to anything sensitive, and security training is part of onboarding and repeated every year.
Company devices are managed, encrypted and monitored, work accounts use a password manager with unique credentials, and access is revoked the same day someone leaves.
10. Compliance
Our controls are audited against the SOC 2 Trust Services Criteria. Payments stay inside PCI DSS Level 1 certified providers, so card data never touches our infrastructure.
We meet CCPA and CPRA obligations for California residents, GDPR obligations where it applies, and GLBA requirements for nonpublic financial information. The product is built to support fair housing compliance in every leasing workflow.
11. Business continuity
Rentier runs across multiple availability zones with automatic failover. We target a recovery time under four hours and a recovery point under one hour.
Encrypted backups are restored in regular drills rather than assumed to work, uptime is monitored around the clock, and service-impacting events are posted on the status page and emailed to affected customers.
12. Security updates
This page is reviewed at least quarterly and updated whenever our practices change. The date at the top is the date of the last change.
Material changes are announced in the app and by email. To be told about security updates directly, write to [email protected].
Questions about any of the above: [email protected]
