Renewal Book
Security

Your clients' data, handled like it matters.

Your agency holds people's personal information. Here's what protects it, in plain words: only what's in place today.

Signing in

  • Passwords are stored as argon2id hashes, never as the password itself.
  • Two-step sign-in with an authenticator app or a passkey. Owners and admins must use it; an agency can require it of everyone.
  • Sensitive actions (changing an email address, billing, two-step settings) ask for your password or a code again.
  • Repeated failed sign-ins are slowed and then stopped, and each account keeps a list of its recent sign-ins.

Your agency's data, kept apart

  • Each agency's records are separated by the database itself (PostgreSQL row-level security), not only by the application's code.
  • Owners and admins decide who has access, and at what level: admin, agent (makes changes) or view-only.
  • An audit log records who changed what, and when.

Encryption

  • Every connection is encrypted (HTTPS, with HSTS).
  • Documents are stored encrypted at rest, in a private storage bucket with public access blocked.
  • Carrier portal logins and two-step secrets are encrypted in the database with their own keys.

Hosting and backups

  • Hosted on Amazon Web Services in the United States.
  • The database is backed up every day and before every update; backups are kept for 14 days.
  • Uploaded files are checked: a file must really be the type it claims to be before it's accepted.

Your data is yours

  • Export everything, any time, on every plan: every record as spreadsheet files, with a guide to the columns.
  • Deleted records wait 30 days in Recently deleted, so a mistake can be undone.
  • We don't sell data, and we don't use your agency's data for advertising.

Payments

  • Card payments are handled by Stripe. Card numbers never reach our servers.
  • Sign-ups are checked for bots with Cloudflare Turnstile, which uses no tracking cookies.

Who else handles data

A short list of service providers, each with only what it needs: see Sub-processors. How we handle personal information is in the Privacy Policy and the Data Processing Addendum.

Reporting a security issue

Found something? Write to i.shulha@renewal-book.com. We'll reply within two business days and keep you posted until it's fixed. Please don't test against other agencies' data.

Start free, no card