Security / Soc2
SOC 2 Compliance
RentBridge is pursuing SOC 2 Type 1 certification to ensure your data is secure and your business is protected.
What is SOC 2?
SOC 2 (Service Organization Control 2) is a security audit standard from the American Institute of Certified Public Accountants (AICPA).
SOC 2 audits ensure:
- Security controls are in place
- Data is encrypted and protected
- Access is restricted to authorized users only
- Incidents are detected and reported
- Backups work and recovery is possible
- Operations are reliable and available
SOC 2 Type 1: Snapshot of your security at a point in time (6-month audit period) SOC 2 Type 2: Sustained security controls over an extended period (12-month audit)
RentBridge is targeting SOC 2 Type 1 in Q3 2026, with Type 2 to follow in 2027.
Current Status
April 2026: SOC 2 audit in progress.
We're not yet certified, but we're implementing all required controls:
- Encryption in transit and at rest
- Access logging and audit trails
- Incident response procedures
- Data backups and disaster recovery
- Employee security training
What This Means for You
Before SOC 2 (Now)
- Your data is encrypted
- Security is a priority
- But no third-party audit verification
After SOC 2 Type 1 (Q3 2026)
- Independent audit confirms our security
- You get a SOC 2 report (sharable with your auditors)
- Demonstrates compliance to your customers/partners
Use Cases
SOC 2 helps if you need to:
- Prove security to enterprise customers
- Meet compliance requirements (HIPAA, GDPR, etc.)
- Pass your own security audits
- Satisfy enterprise procurement requirements
Current Security Measures
Even without SOC 2 certification, RentBridge implements:
Data Protection
- All data encrypted in transit (HTTPS/TLS)
- Database encryption at rest (AES-256, via Supabase/PostgreSQL)
- Passwords stored as salted hashes — never in plain text
Access Control
- Role-based access control (owner, admin, member) enforced at the API layer
- Short-lived session tokens (30-minute expiry)
- Rate limiting on authentication endpoints to block brute-force attacks
- Organization-scoped data isolation — cross-tenant access is blocked and tested
- Audit logs of sensitive actions (settlements, deposit decisions, agent output)
Infrastructure
- Hosted on US cloud infrastructure (Railway, Vercel, Supabase, Upstash)
- Automated backups
- Error tracking and structured request logging (Sentry + JSON logs)
- Security headers on every response (HSTS, CSP, X-Frame-Options)
Payment Security
- PCI Level 1 compliance via Stripe
- No credit cards stored by RentBridge
- Tokens used for payment processing
- Secure transmission to Stripe's servers
Compliance
- GDPR-compliant (data portability, deletion, consent)
- CCPA-compliant (privacy disclosures, opt-out rights)
- Data processed and stored in US only
- No international transfers
What SOC 2 Won't Cover
SOC 2 audits focus on security, but don't cover:
- Privacy (GDPR/CCPA) — separate compliance
- Accessibility (ADA) — separate standard
- Payment processing (PCI DSS) — Stripe handles this
- Your own data security (your customer responsibility)
We handle privacy and PCI separately. See Data Handling for details.
Request a SOC 2 Report
Once certified (Q3 2026), you can request:
- SOC 2 Type 1 Report — Audit summary (suitable for sharing with auditors)
- Attestation Letter — Confirmation we're SOC 2 compliant
To Request:
- Email: compliance@rentbridge.ai
- Subject: "Request SOC 2 Report"
- Provide: Your company name and reason for request
Reports are issued under an NDA. Enterprise customers can get unrestricted versions.
Upcoming Audits
2026 Timeline
- Q3 2026: SOC 2 Type 1 audit complete, certification issued
- Q4 2026: Start SOC 2 Type 2 audit (12-month control testing)
2027 Plans
- Q2 2027: SOC 2 Type 2 certification issued
- Continued annual audits to maintain certification
HIPAA & Other Standards
RentBridge doesn't currently offer HIPAA-compliant hosting (required for healthcare data). If you need HIPAA compliance, contact compliance@rentbridge.ai to discuss options.
Other standards (ISO 27001, etc.) are not currently pursued but can be evaluated based on customer demand.
Security Incident Response
If we discover a security issue:
- We investigate immediately
- We contain the breach (stop further unauthorized access)
- We notify affected customers (within 24–72 hours)
- We remediate the issue (fix the underlying problem)
- We report to authorities (if required by law)
You can report security issues to compliance@rentbridge.ai.
Transparency
We're committed to transparency:
- Live platform health at the API health endpoint
- Security fixes documented in release notes
- Open communication with customers about incidents
Third-Party Assessments
Beyond SOC 2, we use:
- Vulnerability Scans: Regular penetration testing
- Code Review: Security review of all code changes
- Dependency Updates: Automatic security patches
- Monitoring: 24/7 security monitoring
Security Recommendations for You
Even with RentBridge's security:
- Use Strong Passwords: 16+ characters, unique, no reuse
- One Account Per Person: don't share logins — the audit trail depends on it
- Least Privilege: most staff should be members; reserve admin/owner for those who need it
- Monitor Activity: review audit logs regularly
- Backup Your Data: export CSVs periodically for your own records
- Train Your Team: security starts with people (phishing prevention, etc.)
Questions?
- Security Questions: Email compliance@rentbridge.ai
- Compliance Questions: Email compliance@rentbridge.ai
- SOC 2 Reports: Email compliance@rentbridge.ai (after Q3 2026)
We're happy to discuss your security requirements and how RentBridge can help.
Last Updated: April 2026
SOC 2 Target Completion: Q3 2026
Last updated: April 2026