Your data, protected at every step.
Rentari handles rent, leases, screening, and identity for landlords and property managers. Protecting that information is the product, not an afterthought. Here is exactly how it stays safe, in plain language: encrypted in transit and at rest, separated by role, written to an audit trail, and never sold or used to train AI.
Six layers, working together
Every piece of your data passes through these protections. Here is the short version. Tap any card to see exactly how it works.
Encryption
Encrypted in transit and at rest, with a second key over your most sensitive fields.
Payments
Card details are tokenized by Stripe and never touch our servers.
Access control
Every request is checked against your role, on every route.
Responsible AI
Our AI answers only from your records, and abstains rather than guess.
Listing integrity
Verified identity and proven ownership before anything goes live.
Accountability
An append-only audit trail of every sensitive action you can export.
Encrypted in transit, encrypted at rest.
Two layers, not one. Every request travels over HTTPS with a strict transport policy, and your data sits encrypted at rest on Google Cloud. The most sensitive fields go further: SSNs, dates of birth, tax IDs, and full screening reports are encrypted again with a separate application key before they ever reach the database.
Card details never touch our servers.
We never hold your card data. Card and bank details are tokenized in the browser by Stripe and routed straight to your own connected Stripe account. Rentari never sees, logs, or stores a card number, and every payment carries an idempotency key so a retry can never double charge.
Every request is gated by role.
Least privilege, by default. Landlords, managers, tenants, and vendors each see only what their role allows. A team member is always scoped to the portfolio owner who invited them, tenants and vendors are blocked from landlord finance and document endpoints, and a logged-out or deleted account loses access right away.
Our AI answers from your data, or not at all.
It would rather say it does not know. Luna for tenants and Mozart for landlords are bound by grounding rules. If a fact is not in your records, the AI says so and routes to a human instead of inventing an answer. It never reports a balance it cannot see, never claims an action was taken, and never reveals its own instructions. Your data is not used to train any model.
Verified identity and proven ownership before a listing goes live.
A Verified badge has to be earned. A property cannot publish to the marketplace until the account owner passes a government-ID check through Stripe Identity and the property's ownership is confirmed, either against public records or with documents our team reviews. That is what a Verified badge means: a real, authorized owner.
Every sensitive action is on the record.
If it happened, it is on the record. Sign-ins, payments, refunds, lease changes, screening, and consent are written to an append-only audit log that captures who, what, when, and from where. Admin login-as-anyone has been removed entirely, and you can export your data or request deletion with a recovery grace window at any time.
How your most sensitive data is handled, step by step
Screening identity (an SSN and a date of birth) is the most sensitive thing we touch. Here is the full path it takes, start to finish.
Collected on our own page
We gather the SSN, date of birth, and consent on a Rentari page reached through a signed, time-limited link, never on a third-party site.
Sent over an encrypted connection
It travels over HTTPS with a strict transport policy, so it is encrypted the entire way to our servers.
Encrypted with a separate key
It is stored encrypted at rest behind a dedicated application key, kept apart from the rest of the database.
Used only to run the check
It is sent to an FCRA-accredited screening agency to run the report, and is used for nothing else.
The landlord sees the result only
Your landlord receives a pass or fail outcome. They never see your Social Security number.
Written to the audit trail
Consent is recorded with the signed name, the exact time, the source IP, and the disclosure version shown, for FCRA accountability.
Security status, checked in real time
This card reads our live status endpoint when the page loads, so it reflects the current posture, not a static screenshot.
What we do, and what we promise
The honest version. Some of this is enforced in code today, and some is a commitment about how we will act.
Incident response
If we ever confirm unauthorized access, we revoke and rotate the affected credentials, notify the accounts involved within 72 hours of confirmation, and publish a written summary of what happened and what we changed.
Compliance, inherited and in progress
We run on Google Cloud and Stripe, which are independently certified (SOC 1/2/3, ISO 27001, PCI-DSS Level 1). Our own SOC 2 Type II is in progress. Background and credit checks run through an FCRA-accredited agency.
Procurement and questionnaires
Need a vendor questionnaire (CAIQ, SIG Lite, or your own)? Email [email protected] and we will respond within 5 business days. The full subprocessor list lives on our Trust Center.
Found a vulnerability? Tell us.
We welcome reports from security researchers. Submit below and you get an instant AI-proposed severity before it routes to our team, or email [email protected] directly.
Thank you. Your report has been logged with id . We acknowledge new reports within 2 business days.
Security questions, answered
Where is my data stored?
Who at Rentari.ai can access my account data?
What encryption do you use?
Do you use my data to train AI?
How do I report a vulnerability?
Security you can check, not just take on faith.
See the live posture, browse our subprocessors and compliance posture, or read exactly how we handle your data.
Questions about security or procurement? Email [email protected].