Security at MSP Renewals
Last updated: July 10, 2026
You trust us with data about your clients' security infrastructure. We treat that responsibility as the core of the product — here is how your data is protected.
Tenant isolation
MSP Renewals is multi-tenant with database-level row security (RLS): every record carries your organization's identity, and isolation is enforced by the database itself — not just application code. No other subscriber can view, access, or modify your data.
Encryption
- In transit: all traffic uses TLS/HTTPS
- At rest: AES-256 encryption on all stored data
- Payments: processed by a PCI-DSS Level 1 payment processor; full card numbers never touch our servers
Authentication
- Passkeys (WebAuthn) — phishing-resistant, passwordless sign-in
- Email one-time codes as a fallback — no passwords stored, nothing to leak
- Client quote links are unguessable, single-purpose tokens that expose only that quote
Infrastructure & subprocessors
We run on a small set of vetted, enterprise-grade providers: a SOC 2 Type II-audited database and authentication platform, a PCI-DSS Level 1 payment processor, a dedicated transactional email service, and managed application hosting. Each subprocessor is contractually bound to protect your data and processes it only to provide services to us.
Operational practices
- Least-privilege access: administrative access to production is restricted and audited
- Automated daily backups with point-in-time recovery
- Regular security reviews of authentication, tenant-isolation, and API surfaces
- Scheduled jobs authenticate with rotated secrets stored in an encrypted vault
Reporting a vulnerability
If you believe you've found a security issue, email support@msprenewals.com with “Security” in the subject line. We respond to security reports within 1 business day. Please do not test against other tenants' data — we'll provide a sandbox on request.
For details on what data we collect and how it's used, see our Privacy Policy.