Security
Last updated: July 2026
Overview
RenewShield is privacy-first and does not require bank connections. We use secure authentication, encryption, access controls, audit logs, and account-level privacy controls to protect user data.
SOC 2 readiness
RenewShield is built with privacy and security in mind and is preparing for SOC 2 readiness as we expand toward Team and Business plans. RenewShield is not SOC 2 certified or audited today.
Encryption and access
Profile fields are encrypted at the application layer. Workspace subscription content uses per-workspace encryption keys. Passwords are handled by AWS Cognito; we never store plain-text passwords. Two-factor authentication secrets are encrypted at rest. Sessions use signed tokens. Audit events for subscription and member changes are recorded on every workspace using metadata only; Team+ workspaces can view them in the app.
Infrastructure
Production data is stored in encrypted PostgreSQL (Neon) in the EU. Traffic is served over HTTPS via Vercel. Production errors are monitored with Sentry (no intentional PII). Backups follow our providers’ retention policies.
Reporting issues
If you discover a security concern, email privacy@renewshield.app with details. We will investigate and respond as promptly as practicable.
RenewShield · Operated by Nisha Chavan, Sweden · privacy@renewshield.app · support@renewshield.app