Security
Your clients' data, handled like it matters.
Your agency holds people's personal information. Here's what protects it, in plain words: only what's in place today.
Signing in
- Passwords are stored as argon2id hashes, never as the password itself.
- Two-step sign-in with an authenticator app or a passkey. Owners and admins must use it; an agency can require it of everyone.
- Sensitive actions (changing an email address, billing, two-step settings) ask for your password or a code again.
- Repeated failed sign-ins are slowed and then stopped, and each account keeps a list of its recent sign-ins.
Your agency's data, kept apart
- Each agency's records are separated by the database itself (PostgreSQL row-level security), not only by the application's code.
- Owners and admins decide who has access, and at what level: admin, agent (makes changes) or view-only.
- An audit log records who changed what, and when.
Encryption
- Every connection is encrypted (HTTPS, with HSTS).
- Documents are stored encrypted at rest, in a private storage bucket with public access blocked.
- Carrier portal logins and two-step secrets are encrypted in the database with their own keys.
Hosting and backups
- Hosted on Amazon Web Services in the United States.
- The database is backed up every day and before every update; backups are kept for 14 days.
- Uploaded files are checked: a file must really be the type it claims to be before it's accepted.
Your data is yours
- Export everything, any time, on every plan: every record as spreadsheet files, with a guide to the columns.
- Deleted records wait 30 days in Recently deleted, so a mistake can be undone.
- We don't sell data, and we don't use your agency's data for advertising.
Payments
- Card payments are handled by Stripe. Card numbers never reach our servers.
- Sign-ups are checked for bots with Cloudflare Turnstile, which uses no tracking cookies.
Who else handles data
A short list of service providers, each with only what it needs: see Sub-processors. How we handle personal information is in the Privacy Policy and the Data Processing Addendum.
Reporting a security issue
Found something? Write to i.shulha@renewal-book.com. We'll reply within two business days and keep you posted until it's fixed. Please don't test against other agencies' data.