Access control
Use individual identities, role-based access, and the minimum property scope a person needs.
Security and trust
Rentabe’s security approach starts with limited access, careful data handling, visible ownership, and honest descriptions of current controls.
Security approach
Use individual identities, role-based access, and the minimum property scope a person needs.
Separate guest-facing property details from team-only and sensitive operating information.
Select managed infrastructure and production services with documented security responsibilities.
Prepare detection, assessment, containment, communication, and recovery procedures before launch.
Collect and retain only data needed for the product and operating purpose. Define owners, retention rules, deletion paths, and vendor responsibilities before production processing.
Production deployments should use encryption in transit and appropriate encryption at rest through selected infrastructure and service providers. Verify the exact control set before making a customer commitment.
The public website redirects sign-in and workspace creation to the Rentabe application origin, where passwords are verified server-side and sessions use opaque, hashed tokens in httpOnly cookies. Password recovery remains unavailable unless its server adapter is configured.
Document hosting regions, subprocessors, backups, logging, secrets management, availability expectations, and recovery procedures as the production architecture is finalized.
Maintain a current contact path, internal responsibilities, severity model, evidence handling approach, customer communication plan, and post-incident review process.
To report a potential security issue, email security@rentabe.com with a clear description and safe reproduction details. Do not access data that is not yours or disrupt service.
Use the Privacy page for the current website notice. Product-specific privacy terms, subprocessors, retention periods, and data processing terms should be published before production use.
Ask for current architecture and control details relevant to your deployment.