Security Overview
Rental Flow Inc. (“we”, “us”, “our”) takes the security of your data seriously. This page describes the technical, administrative, and physical safeguards we have implemented to protect the Rental Flow platform (“Service”) and the data you entrust to us.
Security is an ongoing process. We continuously review and enhance our security posture to address emerging threats and industry best practices.
Data Encryption
Data in Transit
All data transmitted between your browser and the Rental Flow platform is encrypted using TLS (Transport Layer Security). We enforce HTTPS across all connections and reject unencrypted requests.
Data at Rest
Your data is stored in encrypted databases on secure cloud infrastructure. Database volumes are encrypted using industry-standard AES-256 encryption.
Credential Storage
User passwords are never stored in plaintext. We use industry-standard hashing algorithms to protect authentication credentials. OAuth tokens for integrations like QuickBooks are stored securely and encrypted at rest.
Access Control
Authentication
Access to the platform requires authenticated sessions. We support secure session management with automatic expiration. Multi-factor authentication may be enforced for administrative accounts.
Role-Based Access Control
Rental Flow implements role-based access control (RBAC) within each tenant. Users are assigned roles (owner, manager, sales, mechanic, accountant, viewer) with specific permissions. Tenant isolation ensures that data from one company is never accessible to users of another company.
Least Privilege
Internal access to production systems follows the principle of least privilege. Access is granted on a need-to-know basis and is regularly reviewed and revoked when no longer required.
Infrastructure Security
Rental Flow is hosted on secure cloud infrastructure providers that maintain industry-recognized security certifications including SOC 2 Type II, ISO 27001, and PCI DSS compliance.
Our infrastructure is continuously monitored for unauthorized access, unusual activity, and potential security events. Security patches and updates are applied on a regular schedule.
Integration Security
QuickBooks Online
QuickBooks OAuth tokens are stored securely and encrypted at rest. We only access your QuickBooks data with your explicit authorization, and only to perform the sync operations you initiate. Tokens are automatically refreshed and are purged when you disconnect the integration.
DocuSign
DocuSign integration uses secure API authentication. Contract documents are transmitted over encrypted channels for electronic signature processing.
Email Delivery
Email delivery services used to send invoices, statements, and notifications operate over encrypted connections. Email content is transmitted for delivery purposes only and is not retained by the email provider beyond what is necessary for delivery.
Monitoring and Logging
We maintain audit logs of key platform activities including authentication events, data access, and integration operations. Logs are reviewed for anomalies and retained according to our data retention policy.
Automated monitoring alerts our team to suspicious activity, failed authentication attempts, and potential security incidents in real time.
Incident Response
Rental Flow maintains an incident response plan to detect, assess, and respond to security incidents. In the event of a confirmed data breach affecting your data, we will notify affected customers without undue delay in accordance with applicable legal requirements.
Our incident response procedures include containment, investigation, remediation, and post-incident review to prevent recurrence.
Data Backup and Recovery
Your data is backed up regularly to enable recovery in the event of data loss or system failure. Backups are encrypted and stored in geographically separated locations to ensure availability.
We conduct periodic recovery testing to validate the integrity and restorability of our backups.
Compliance and Certifications
Rental Flow is designed to align with industry security standards and best practices, including SOC 2 controls, PIPEDA (Canada), and GDPR (European Union) data protection principles.
We work with our cloud infrastructure and service providers to maintain compliance with applicable security and privacy frameworks.
Responsible Disclosure
If you believe you have discovered a security vulnerability in Rental Flow, we encourage you to report it responsibly. Please contact us at security@rentalflow.ca with a detailed description of the issue.
We ask that you do not publicly disclose the vulnerability until we have had an opportunity to investigate and remediate it. We are committed to acknowledging and addressing legitimate reports in a timely manner.
Security Contact
For security-related inquiries, vulnerability reports, or questions about this page, please contact:
Rental Flow Inc.
Email: security@rentalflow.ca