Security & trust

Protection enforced by the database itself — not by promises.

One operator’s rows can never reach another’s screen. Evidence can’t be edited after the fact. Card numbers never touch our servers. Here’s exactly how.

Tenant isolation

One fleet’s data cannot leak into another’s.

Most platforms filter tenants in application code and hope every query remembers to. Rentavoq filters below the application, where a bug can’t forget.

Row-level security in Postgres

Every tenant-scoped query is filtered inside the database, below the ORM. An application bug can’t return another operator’s rows — the database refuses to.

Sessions never share

Tenant context resolves per request from your subdomain or organization claim. Renter storefront sessions and operator sessions are kept fully separate.

A test that fails the build

An automated multi-tenant isolation test runs in CI on every change. Any cross-tenant read or write fails the build before it can ever ship.

Evidence & audit

Records that can’t be rewritten.

Deposits, claims, and key releases all rest on evidence. So the evidence is append-only — written once, never edited, never quietly deleted.

Immutable verification evidence

Every check — insurance, identity, contract, deposit, inspection — writes a timestamped record with provider, payload hash, result, and expiry. Key release is computed from those records. There is no manual override.

Append-only claim history

Every claim state change writes an immutable audit entry: photos, AI output, captures, and communications. Financial, inspection, and signature records follow the same append-only rule.

Admin actions on the record

Every privileged action lands in an exportable, append-only log — who, what, when. MFA is forced on all admin logins, and support access is consent-noted and fully logged.

Data handling

Encrypted everywhere. Collected sparingly.

The safest data is data we never hold. What we do hold is encrypted in transit, at rest, and — for the most sensitive fields — at the column level.

Card data lives with Stripe

Payments run through Stripe’s hosted fields, so Rentavoq qualifies for the lightest PCI posture (SAQ A). Full card numbers never touch our servers — we keep tokens and the last 4 digits only.

Encryption in transit and at rest

TLS 1.2+ on every connection and AES-256 at rest. Sensitive columns — driver’s-license numbers, dates of birth — carry their own additional encryption layer.

Secrets under management

Credentials and API keys live in a vault with rotation, and each operator’s integration credentials are encrypted with dedicated key management.

Biometrics stay with the provider

ID and selfie verification runs at the verification provider. Rentavoq stores a reference to the result — not the biometric data itself. We keep the pass, not your face.

Minimum necessary ID data

Verification collects what a rental decision needs and nothing more. Biometric identifiers are retained by providers only as long as the verification purpose requires.

Accessible by design

Every surface — operator app, storefronts, admin — targets WCAG 2.1 AA, and status is never conveyed by color alone.

Vendors & commitments

Your renters’ data is processed, never sold.

For renter data, your business is the controller and Rentavoq is your service provider — we process it only on your documented instructions, and we never sell or share it.

Every subprocessor is named, U.S.-based, and bound by contract terms no less protective than our DPA.
Security incidents: notice without undue delay, with a 72-hour target.
On termination, your data is exportable for 30 days, then deleted per the DPA.
Named subprocessors
Stripe — payments, deposit holds, and identity checksCanopy Connect — insurance verificationBouncie — vehicle telematicsPersona — identity and document verificationTwilio — SMSPostmark — email

The full list, with data categories per vendor, lives in the data processing addendum.

Honest limits

What we don’t claim.

Trust pages love borrowed badges. Here’s what we won’t put on this one — yet.

No SOC 2 badge today. SOC 2 readiness is on the roadmap. Until an auditor has signed, we publish our actual practices — the ones on this page — instead of a logo.

No uptime number yet. Availability targets and service credits are being finalized in the operator subscription agreement. We’d rather publish a real commitment than a marketing figure.

A platform, not an insurer. Rentavoq verifies coverage, holds deposits, and keeps the evidence. It does not insure vehicles, approve or deny renters, or decide claims — those decisions stay with you and your carriers.

Questions welcome

Put our answers in writing.

Running a security review or a vendor questionnaire? Send it over. You’ll get plain-language answers, in writing, from the people who built the system.

Email the security teamRead the DPA

Run your fleet on rails that refuse to bend.

14-day free trial · No card required · $0 setup
Start free trial