Permission receipt
Read-only bank feed
Transactions: allowed
Dates, descriptions, amounts, currencies, and transaction status for categorization, bookkeeping, reconciliation, and reporting. Stripe also supplies the institution, account type or nickname, and last four digits needed to identify the selected account.
Balances: authorized, not active
Current and available balance access is reserved solely for a future bank- reconciliation workflow. Rentium does not currently prefetch, refresh, retrieve, store, or display balances.
Ownership / full account numbers / money movement: not requested.
Stripe authenticates access inside its hosted institution flow. Rentium requests no ACH credentials, verification or tokenization product, payment initiation, or debit authorization through this read-only connection. Those bank-feed permissions remain separate from rent-payment setup and money movement.
Feed provider: Stripe Financial Connections. Disconnecting stops future feed access; it does not itself delete data previously shared with or retained by Rentium or Stripe.
See the privacy deletion process for requests involving data Rentium controls. Stripe retention remains subject to its own terms and applicable law.
Control 01
A narrow, documented data boundary
Rentium's program covers production systems, source code, credentials, devices, vendors, and people that can store, process, transmit, or administer customer data. Bank transaction data receives the highest internal sensitivity classification.
Bank-feed data currently retrieved and retained is limited to transaction dates, descriptions, amounts, currencies, lifecycle status, and the institution, account type or nickname, and last four digits needed to identify the selected account. Rentium also requests balance access solely for a future bank-reconciliation workflow, but does not currently prefetch, refresh, retrieve, store, or display balances. Bank data is not sold, used for advertising, or used as a consumer report.
Control 02
Least privilege from sign-in to storage
- Individual administrative accounts use multi-factor authentication where supported; shared administrative credentials are prohibited.
- Customer access is scoped by authenticated workspace membership, portfolio capabilities, and database tenant-isolation constraints.
- While Rentium is founder-operated, production database and provider-console access is restricted to the founder and reviewed quarterly.
- Secrets stay in provider-managed configuration, never source control, and are rotated after suspected exposure.
- Anyone—including the founder—who can access unencrypted bank data completes an appropriate background check where law permits before live access.
- Customer data uses current TLS in transit and managed encryption at rest. Administrative devices use full-disk encryption, automatic locking, supported software, and current security updates.
Control 03
Dated checks with explicit remediation
| Control | Minimum cadence |
|---|---|
| Dependency, configuration, secret, and exposure review | Monthly |
| Security and bank-data risk self-assessment, vulnerability review, access, and subprocessors | Quarterly and after a material change |
| Penetration exercise combining automated testing with manual abuse-case review | Annually and after a material change to the bank-data boundary |
| Incident-response tabletop and restore exercise | Annually |
Each finding receives an owner, severity, remediation decision, and verification evidence. Critical exposure or active compromise blocks the affected release or feature; high-risk findings target 14 days and medium-risk findings target 30 days.
Control 04
Production bank data stays out of incidental systems
- Live customer bank data is not copied into development or test systems.
- Authenticated, workspace-scoped Rentium UI and REST endpoints expose imported bank transaction data to users with the required portfolio capability. Those are intentional product surfaces, not incidental disclosure.
- When independently enabled, the built-in assistant and a user-connected tool or agent may receive limited transaction data to review activity, change coding, manage deterministic rules, or request a refresh, with the same authorization and portfolio scope. Those surfaces cannot link, complete, or disconnect bank feeds; retrieve balances, full account details, credentials, or identity documents; or move money.
- Agent calls are ordinary authenticated API requests made at the user's direction, not a second bank-connection consent pathway. When enabled, built-in assistant bank requests use no-collection and zero-data-retention routing. External tools or agents are selected by the user, and their terms govern copies after delivery. Bank data remains excluded from product analytics, logs, error payloads, email, support tooling, and other incidental telemetry.
- Stripe client secrets are never rendered into HTML, logged, toasted, or stored by the browser. Signed webhooks are verified, deduplicated, and handled through a durable retry path.
- Changes are version-controlled and tested for authorization, tenant isolation, provider failure, duplicate delivery, and lifecycle behavior proportionate to the change.
Control 05
Contain first, notify with known facts
Security-relevant access and operational events are monitored without recording bank content. Suspected unauthorized access, loss, use, disclosure, or modification is contained, investigated, preserved as evidence, eradicated, recovered, and followed by a written retrospective.
If an incident may involve Stripe Connections Data, Rentium notifies Stripe immediately through its designated incident channel. Affected users and authorities are notified as required by law and contract, with updates as the facts develop.
Control 06
Server-side Connections Data stays in the 50 states and D.C.
Rentium's location commitment applies to provider and server-side storage of Connections Data—including server-side replicas, backups, logs, and derived copies. Those systems remain within the 50 U.S. states and the District of Columbia unless Stripe gives written approval for another location.
An authorized user may view or download their data on a device from another location. That user-controlled device access is not a claim that every local copy remains within the server-side storage boundary.
Rentium reviews providers it appoints to process customer data for their safeguards, location, incident terms, retention, subprocessors, and contract. Material providers are re-reviewed annually and after a significant incident or contract change. A tool or agent a user connects is a user-directed delivery, and that provider's terms govern its copy after delivery. Rentium will maintain cyber insurance reasonable for its live data volume, exposure, and contractual requirements before processing live bank Connections Data.
Control 07
What this program does—and does not—claim
Rentium is a founder-operated service. This page is not a claim that Rentium is SOC 2, ISO 27001, PCI, or independently audited or certified. Self-performed and automated-tool-assisted work is recorded as such, not represented as an independent third-party assessment.
An independent assessment may be commissioned when risk, a customer agreement, law, or a provider requires it. Until then, the control cadences above are the commitments Rentium can support and evidence.
Control 08
A clear channel before live collection
A dedicated public security-reporting address has not yet been published. Rentium will add it here before live bank-data collection begins. Private-preview users should use the support channel supplied with their account and should never include bank credentials or transaction details in a report.
Good-faith reports will be investigated and coordinated without retaliation. A material change to the purpose, scope, sharing, security, or retention of bank data requires a new consent version and provider review before it takes effect.