Security at Rentsync

Governance

Rentsync’s Security and Privacy team establishes policies and controls, monitors compliance with those controls, and is working towards proving our security and compliance to third-party auditors.

Our policies are based on the following foundational principles: 

  1. Access should be limited to only those with a legitimate business need and granted based on the principle of least privilege.
  2. Security controls should be implemented and layered according to the principle of defense-in-depth.
  3. Security controls should be applied consistently across all areas of the enterprise.
  4. The implementation of controls should be iterative, continuously maturing across the dimensions of improved effectiveness, increased auditability, and decreased friction.

Data Protection

Rentsync uses TLS 1.2 or higher everywhere data is transmitted over potentially insecure networks. We also use features such as HSTS (HTTP Strict Transport Security) where possible to maximize the security of our data in transit. Server TLS keys and certificates are managed by AWS for client websites, and Google for the Rentsync Platform, and are deployed via Load Balancers.

Product Security

Rentsync regularly engages with leading penetration testing organizations to conduct comprehensive penetration tests periodically. All areas of the Rentsync Platform are tested, and source code is fully available to the testers in order to maximize the effectiveness of testing. 

Rentsync also utilizes several vulnerability scanning tools internally as well to continuously monitor our code and software. 

  1. Static application security testing of code (SAST)
  2. Software composition analysis (SCA) to identify known vulnerabilities in our software supply chain
  3. Malicious dependency scanning to prevent the introduction of malware into our software supply chain
  4. Dynamic analysis of running applications (DAST)
  5. Network vulnerability scanning multiple times daily

Infrastructure Security

Rentsync takes various steps to ensure our infrastructure is secured and protected from various internal and external threats. 

  • Ensuring the use of an IDS (Intrusion Detection System) or IPS (Intrusion Prevention System) on all production networks
  • Network/host vulnerability scanning is performed at least monthly
  • Use of encryption technologies to encrypt data in transit and at rest when applicable
  • Strict access control mechanisms for infrastructure access
  • Ensuring production workloads reside within Canadian data centers, where applicable
  • Using performance and availability monitoring technologies to monitor for system issues, and ensuring both availability and security alerts are monitored and addressed quickly
  • For public-facing web applications Rentsync provides, a WAF (web application firewall), is positioned in front of servers to provide an additional layer of security

Enterprise Security

All corporate devices are centrally managed and are equipped with mobile device management software and anti-malware protection. Endpoint security alerts are monitored 24/7/365. We use MDM software to enforce secure configuration of endpoints, such as disk encryption, screen lock configuration, and software updates.

Rentsync provides comprehensive security training to all employees upon onboarding and quarterly through a 3rd party training platform, KnowBe4. 

Rentsync’s security team shares regular threat briefings with employees to inform them of important security and safety-related updates that require special attention or action.

Rentsync's security team also owns and operates the incident management process, ensuring the processes are kept up to date and utilized when needed.

Responsible Disclosure

Looking to report a security concern? Please email [email protected]. We’ll acknowledge your email within 1 week. 

Trust Report

Learn more about Rentsync’s cybersecurity posture, and compliance by visiting our Trust Report at: Trust Center