Security & Trust Center

The proof, not the promises. Every claim on this page links to the partner, certificate, or policy that backs it.

Checking system status...

Verified controls

Last reviewed: Apr 2026

Encryption at rest and in transit

Active

AES-256 at rest via Google Cloud KMS, TLS 1.3 in transit. Database, object storage, and backups are all encrypted with isolated keys.

Google Cloud compliance reports

PCI-DSS Level 1 via Stripe

Active

We never see or store card or bank numbers. Stripe Elements tokenizes payment data in the browser. Your tenants pay directly into your Stripe Connect account.

Stripe security overview

FCRA-compliant tenant screening

Active

Background and credit reports are run by an FCRA-accredited consumer reporting agency. We auto-generate FHA-compliant adverse action notices and keep a 7-year audit log.

SOC 2 Type II

In progress

Observation window opened Q1 2026 with Vanta. Report expected Q4 2026. We will share the executive summary on request under NDA.

Request status update

GDPR and CCPA

Active

Data export and deletion requests honored within 30 days. CCPA "Do Not Sell" toggle is one click. We do not sell tenant or landlord data to anyone, ever.

Do Not Sell My Info

Annual penetration test

Active

Third-party black-box and authenticated pen test runs every 12 months. Last test: Feb 2026. Zero criticals, two highs remediated within 14 days.

Request summary letter

How we run AI responsibly

The hard questions, answered

AI proposes. You decide.

Every AI output in Rentari.ai, listing copy, lease drafts, screening recommendations, late-fee notices, is a draft for your review. Nothing goes to a tenant, a payment processor, or a court without an explicit click from you. The model is a junior assistant, not a decision-maker.

Model and provider

Disclosed

Google Gemini (Flash and Pro tiers) running on Google Vertex AI in US regions. No third-party AI providers. No data leaves Google Cloud.

Vertex AI data governance

Your data is not training data

Contractual

Vertex AI's enterprise terms forbid Google from using your prompts, leases, tenant info, or financials to train foundation models. Inputs and outputs are not retained beyond the request.

Read the policy

Fair Housing guardrails

Active

AI-drafted listing copy and tenant communications are scanned for protected-class language (race, religion, familial status, disability, national origin) before display. Flagged terms are blocked, not silently rewritten.

Equal housing commitment

FCRA adverse-action audit log

7-year retention

Every screening decision logs the inputs the AI saw, the score it returned, the threshold you set, and your final approve/deny. Pull a per-applicant report any time, including the auto-generated adverse-action notice that went to the applicant.

Open screening dashboard

PII redaction before prompting

Active

SSNs, full bank numbers, and government IDs are stripped from prompts before they reach the model. The AI sees "tenant earns 3.1x rent," not the underlying pay stub.

Off switch, per workspace

Available

If you do not want AI touching your portfolio, disable it from Settings. Listing drafts, screening summaries, and copilot chat all stop calling the model. The rest of Rentari.ai keeps working.

AI settings

Sub-processors

Updated when we add or remove a vendor · Last reviewed

The services we trust with your data. Each row links to the vendor's own privacy or compliance page.

Subscribe to changes
Vendor Purpose Data Region
Google Cloud PlatformHosting, database, storage, KMSAllUS
StripePayments, payouts, ConnectPayment instruments, payout detailsUS
CheckrBackground and credit checksApplicant SSN, DOB, addressUS
Google Vertex AI (Gemini)AI drafts, document extractionListing copy, lease text. Not used for training.US
TwilioSMS notifications, 2FA codesPhone numbersUS
SendGridTransactional emailEmail addresses, message bodiesUS
Built to be trusted

Your data, encrypted and on the record.

Bank-grade encryption, a complete audit trail, and one promise that does not change: you own your data.

Rentari.ai trust and security: encryption and a complete audit trail
FAQ

Trust questions every landlord asks

Who actually owns Rentari.ai?
Rentari.ai is operated by ISBAH 360 LLC, a Missouri company. Ownership and key team members are listed on the About page.
How does Rentari.ai make money?
Per-unit subscription is the only platform fee. Tenant screening passes through the bureau cost plus a small margin to the applicant. Rent collection has zero platform fee on the landlord side.
Can I export my data if I leave?
Yes. CSV export of every record (properties, units, leases, tenants, ledger, documents) is available from the dashboard at any time, including after cancellation. We do not hold your data hostage.
What happens to my tenants if I cancel Rentari.ai?
Tenants stay in their unit. Their lease, payment history, and any active autopay agreements are exported to you and disabled inside Rentari.ai. We notify each tenant 30 days before access ends so they can update their payment method with you directly.
Is Rentari.ai regulated?
Tenant screening complies with the Fair Credit Reporting Act. Payments are processed by Stripe, a regulated US money transmitter. Lease drafting is editorially reviewed against each state's current statutes. We are not a law firm, a bank, a real-estate broker, or a property management firm.