Security at MSP Renewals

Last updated: July 10, 2026

You trust us with data about your clients' security infrastructure. We treat that responsibility as the core of the product — here is how your data is protected.

Tenant isolation

MSP Renewals is multi-tenant with database-level row security (RLS): every record carries your organization's identity, and isolation is enforced by the database itself — not just application code. No other subscriber can view, access, or modify your data.

Encryption

  • In transit: all traffic uses TLS/HTTPS
  • At rest: AES-256 encryption on all stored data
  • Payments: processed by a PCI-DSS Level 1 payment processor; full card numbers never touch our servers

Authentication

  • Passkeys (WebAuthn) — phishing-resistant, passwordless sign-in
  • Email one-time codes as a fallback — no passwords stored, nothing to leak
  • Client quote links are unguessable, single-purpose tokens that expose only that quote

Infrastructure & subprocessors

We run on a small set of vetted, enterprise-grade providers: a SOC 2 Type II-audited database and authentication platform, a PCI-DSS Level 1 payment processor, a dedicated transactional email service, and managed application hosting. Each subprocessor is contractually bound to protect your data and processes it only to provide services to us.

Operational practices

  • Least-privilege access: administrative access to production is restricted and audited
  • Automated daily backups with point-in-time recovery
  • Regular security reviews of authentication, tenant-isolation, and API surfaces
  • Scheduled jobs authenticate with rotated secrets stored in an encrypted vault

Reporting a vulnerability

If you believe you've found a security issue, email support@msprenewals.com with “Security” in the subject line. We respond to security reports within 1 business day. Please do not test against other tenants' data — we'll provide a sandbox on request.

For details on what data we collect and how it's used, see our Privacy Policy.