Renaska|Security & Trust

How we protect your data and your customers' data. Full transparency, no fine print.

In plain words

What we do to protect you, explained without jargon.

Your conversations are private

Everything sent and received is encrypted in transit, like a sealed envelope. Not even we can read it along the way.

Your data stays separate

Your business data lives in its own isolated space. It never mixes with another company's data, even on shared infrastructure.

Only the right people get in

Your admins need two steps to log in — like having a key and a code. And each person only sees what they need for their role.

We tell you if something happens

If we detect a security issue that affects you, we notify you within 72 hours. It's the law, and it's the right thing to do.

Your data is always recoverable

We keep automatic backups for 30 days. If something goes wrong, we can restore your data to exactly how it was at any point in time.

Your data belongs to you

You can export, correct, or delete all your information at any time. No fine print, no lock-in.

Compliance

SOC 2 Type II
In progress
ISO 27001:2022
In progress
GDPR / RGPD
Compliant

At a glance

24
Controls
17
Policies
365
Log days
72h
Breach notice

Controls

All controls implemented and tracked.

Infrastructure security

  • TLS 1.2+ encryption in transit
  • AES-256 encryption at rest
  • Per-tenant isolation (PostgreSQL schemas)
  • Continuous PITR — 30-day window (Neon)

Access control

  • Mandatory MFA for admins
  • Role-based access control (RBAC)
  • Quarterly access reviews
  • Employee offboarding < 24h

Monitoring & audit

  • PII access logs — 365-day retention
  • Privileged admin action audit trail
  • Incident response SLA P1 < 4h
  • Breach notification ≤ 72h (GDPR Art. 33)

Development security

  • Dependabot — weekly dependency scanning
  • npm audit blocks high/critical CVEs in CI
  • Semgrep SAST on every Pull Request
  • Branch protection — PR required for main

Privacy & legal

  • DSAR endpoints — data export and erasure
  • Records of Processing Activities (RoPA)
  • Data Processing Agreement (DPA)
  • 30-day notice before subprocessor changes

Security policies

  • 17 policies documented and versioned in git
  • Business continuity & DR plan
  • Responsible disclosure policy
  • Risk register — tracked in database

Subprocessors

Third parties that process personal data on our behalf. We give 30 days notice before adding or replacing a subprocessor.

Loading subprocessors...