Security

Last updated: July 2026

Overview

RenewShield is privacy-first and does not require bank connections. We use secure authentication, encryption, access controls, audit logs, and account-level privacy controls to protect user data.

SOC 2 readiness

RenewShield is built with privacy and security in mind and is preparing for SOC 2 readiness as we expand toward Team and Business plans. RenewShield is not SOC 2 certified or audited today.

Encryption and access

Profile fields are encrypted at the application layer. Workspace subscription content uses per-workspace encryption keys. Passwords are handled by AWS Cognito; we never store plain-text passwords. Two-factor authentication secrets are encrypted at rest. Sessions use signed tokens. Audit events for subscription and member changes are recorded on every workspace using metadata only; Team+ workspaces can view them in the app.

Infrastructure

Production data is stored in encrypted PostgreSQL (Neon) in the EU. Traffic is served over HTTPS via Vercel. Production errors are monitored with Sentry (no intentional PII). Backups follow our providers’ retention policies.

Reporting issues

If you discover a security concern, email privacy@renewshield.app with details. We will investigate and respond as promptly as practicable.

RenewShield · Operated by Nisha Chavan, Sweden · privacy@renewshield.app · support@renewshield.app