Security & Compliance

Your rent roll and financial data are confidential. We treat them that way.

Property managers share some of the most sensitive operational data in their business when they connect a PMS. Rentnoi's architecture is designed with that responsibility in mind — from read-only credentials to role-based access to audit logging.

Security controls

How Rentnoi protects your data

Encrypted data in transit and at rest
TLS 1.3 for all data in transit. AES-256 encryption for data at rest. All PMS credentials stored encrypted, never in plaintext.
Read-only PMS credentials
Rentnoi uses read-only API credentials with the minimum data scope required for NOI analytics. We never write back to your property management system. Your source data is never modified.
Role-based access controls
Team members see only the data their role requires. Portfolio-level access for asset managers. Property-level access for site teams. Configurable by your administrator.
Audit log for all data access events
Every data access event — query, export, dashboard view — is logged with timestamp, user, and IP address. Audit logs are available to your account administrator.
Data residency in US-based infrastructure
All customer data is stored in US-based cloud infrastructure. No data transfer to international data centers.
Secure multi-tenant isolation
Customer data is logically isolated at the tenant level. Your portfolio data is never accessible by another Rentnoi customer, and vice versa.
Compliance status

Compliance posture

We're transparent about where we are. Rentnoi is an angel-backed company — we are actively building toward SOC 2 Type II. We do not claim certifications we have not earned.

Framework Status Notes
SOC 2 Type II In progress Designed with SOC 2 controls in mind. Formal audit not yet initiated — angel-backed. We will update this page when audit begins.
CCPA (California Consumer Privacy Act) Compliant Data handling practices aligned with CCPA. See our Privacy Policy for CCPA-specific disclosures.
GDPR Not primary market US market focus. EU data subjects may contact us at [email protected].
Data practices

What data Rentnoi holds and why

Rentnoi holds a copy of the data it pulls from your property management system for the purpose of computing analytics and serving dashboards. Specifically:

  • Rent roll snapshots — unit-level rent, lease dates, occupancy status. Used to compute occupancy analytics and rent gap analysis.
  • GL expense records — line-item expenses by category and vendor. Used to compute expense variance and benchmarking.
  • Lease records — start/end dates, terms, renewal status. Used for expiration forecasting and renewal probability scoring.
  • Account and user data — name, email, role. Used for authentication and access control.

We do not hold resident personal information (names, contact details, SSNs, payment data). Rentnoi reads operational and financial data — not resident PII from your PMS.

Data retention: operational data is retained for the duration of your subscription plus 30 days. Upon cancellation, data is deleted within 30 days at your request.

Questions about data security?

Our team is happy to walk through specific data handling questions before a purchase decision.