Security / Soc2

SOC 2 Compliance

RentBridge is pursuing SOC 2 Type 1 certification to ensure your data is secure and your business is protected.

What is SOC 2?

SOC 2 (Service Organization Control 2) is a security audit standard from the American Institute of Certified Public Accountants (AICPA).

SOC 2 audits ensure:

  • Security controls are in place
  • Data is encrypted and protected
  • Access is restricted to authorized users only
  • Incidents are detected and reported
  • Backups work and recovery is possible
  • Operations are reliable and available

SOC 2 Type 1: Snapshot of your security at a point in time (6-month audit period) SOC 2 Type 2: Sustained security controls over an extended period (12-month audit)

RentBridge is targeting SOC 2 Type 1 in Q3 2026, with Type 2 to follow in 2027.

Current Status

April 2026: SOC 2 audit in progress.

We're not yet certified, but we're implementing all required controls:

  • Encryption in transit and at rest
  • Access logging and audit trails
  • Incident response procedures
  • Data backups and disaster recovery
  • Employee security training

What This Means for You

Before SOC 2 (Now)

  • Your data is encrypted
  • Security is a priority
  • But no third-party audit verification

After SOC 2 Type 1 (Q3 2026)

  • Independent audit confirms our security
  • You get a SOC 2 report (sharable with your auditors)
  • Demonstrates compliance to your customers/partners

Use Cases

SOC 2 helps if you need to:

  • Prove security to enterprise customers
  • Meet compliance requirements (HIPAA, GDPR, etc.)
  • Pass your own security audits
  • Satisfy enterprise procurement requirements

Current Security Measures

Even without SOC 2 certification, RentBridge implements:

Data Protection

  • All data encrypted in transit (HTTPS/TLS)
  • Database encryption at rest (AES-256, via Supabase/PostgreSQL)
  • Passwords stored as salted hashes — never in plain text

Access Control

  • Role-based access control (owner, admin, member) enforced at the API layer
  • Short-lived session tokens (30-minute expiry)
  • Rate limiting on authentication endpoints to block brute-force attacks
  • Organization-scoped data isolation — cross-tenant access is blocked and tested
  • Audit logs of sensitive actions (settlements, deposit decisions, agent output)

Infrastructure

  • Hosted on US cloud infrastructure (Railway, Vercel, Supabase, Upstash)
  • Automated backups
  • Error tracking and structured request logging (Sentry + JSON logs)
  • Security headers on every response (HSTS, CSP, X-Frame-Options)

Payment Security

  • PCI Level 1 compliance via Stripe
  • No credit cards stored by RentBridge
  • Tokens used for payment processing
  • Secure transmission to Stripe's servers

Compliance

  • GDPR-compliant (data portability, deletion, consent)
  • CCPA-compliant (privacy disclosures, opt-out rights)
  • Data processed and stored in US only
  • No international transfers

What SOC 2 Won't Cover

SOC 2 audits focus on security, but don't cover:

  • Privacy (GDPR/CCPA) — separate compliance
  • Accessibility (ADA) — separate standard
  • Payment processing (PCI DSS) — Stripe handles this
  • Your own data security (your customer responsibility)

We handle privacy and PCI separately. See Data Handling for details.

Request a SOC 2 Report

Once certified (Q3 2026), you can request:

  1. SOC 2 Type 1 Report — Audit summary (suitable for sharing with auditors)
  2. Attestation Letter — Confirmation we're SOC 2 compliant

To Request:

Reports are issued under an NDA. Enterprise customers can get unrestricted versions.

Upcoming Audits

2026 Timeline

  • Q3 2026: SOC 2 Type 1 audit complete, certification issued
  • Q4 2026: Start SOC 2 Type 2 audit (12-month control testing)

2027 Plans

  • Q2 2027: SOC 2 Type 2 certification issued
  • Continued annual audits to maintain certification

HIPAA & Other Standards

RentBridge doesn't currently offer HIPAA-compliant hosting (required for healthcare data). If you need HIPAA compliance, contact compliance@rentbridge.ai to discuss options.

Other standards (ISO 27001, etc.) are not currently pursued but can be evaluated based on customer demand.

Security Incident Response

If we discover a security issue:

  1. We investigate immediately
  2. We contain the breach (stop further unauthorized access)
  3. We notify affected customers (within 24–72 hours)
  4. We remediate the issue (fix the underlying problem)
  5. We report to authorities (if required by law)

You can report security issues to compliance@rentbridge.ai.

Transparency

We're committed to transparency:

  • Live platform health at the API health endpoint
  • Security fixes documented in release notes
  • Open communication with customers about incidents

Third-Party Assessments

Beyond SOC 2, we use:

  • Vulnerability Scans: Regular penetration testing
  • Code Review: Security review of all code changes
  • Dependency Updates: Automatic security patches
  • Monitoring: 24/7 security monitoring

Security Recommendations for You

Even with RentBridge's security:

  1. Use Strong Passwords: 16+ characters, unique, no reuse
  2. One Account Per Person: don't share logins — the audit trail depends on it
  3. Least Privilege: most staff should be members; reserve admin/owner for those who need it
  4. Monitor Activity: review audit logs regularly
  5. Backup Your Data: export CSVs periodically for your own records
  6. Train Your Team: security starts with people (phishing prevention, etc.)

Questions?

We're happy to discuss your security requirements and how RentBridge can help.


Last Updated: April 2026
SOC 2 Target Completion: Q3 2026

Last updated: April 2026