SOC 2 hosting and security controls
SOC 2 is an independent audit of how a company protects data. Renewly runs on hosting that holds a SOC 2 Type II report. This page explains what that means, and the security controls we add on top.
What is certified, and what is not
- Our hosting providers (Supabase and Vercel) hold SOC 2 Type II certification. Renewly itself is not in audit scope; the certifications belong to our infrastructure vendors.
- Supabase is certified to ISO/IEC 27001:2022 across its full information security management system. Renewly itself is not in audit scope.
In short: our hosting providers are certified. Renewly as a company does not hold its own SOC 2 or ISO 27001 certificate. If your security review needs more detail, the full list of providers and what each one does is on the trust page.
Encryption
Encryption scrambles data so only authorised systems can read it.
- Stored data: everything in our database and file storage is encrypted with AES-256.
- Data on the move: connections to Renewly are encrypted with TLS 1.3. Browsers are told to use a secure connection every time, for a year after each visit.
- Connection secrets: the keys Renewly holds for your connected services get a second layer of encryption inside the app. This covers calendar connections (Google and Outlook), Salesforce and DocuSign connections, the addresses Renewly uses to post to Slack or Microsoft Teams, and your single sign-on certificate.
Who can see what
- Each organisation's data is kept separate. Access rules in the database itself stop one organisation from reading another's contracts.
- Everyone in a team has a role: Owner, Admin, Member or Viewer. The role decides what they can do. See Teams.
- You can also limit members to the contracts of their own department. See Departments.
Signing in
- Renewly has no passwords. People sign in with an emailed link, with Google or Microsoft, or with a passkey (fingerprint, face or security key).
- Two-factor authentication with an authenticator app is available to everyone. Sensitive actions, such as exporting data, ask you to confirm with it or with a passkey.
- Single sign-on (SSO): owners and admins can save their identity provider's details today, but sign-in through it is not live yet. See SSO/SAML setup.
Activity Log
The Activity Log records who did what in your workspace and when, with the IP address (the network address the request came from) where one is available. You can filter it by event type and date range. On the Business and Enterprise plans you can also export it.
We keep the audit log for at least 3 years. No setting can shorten that.
Security Events
The Security Events page is a shorter list of security-related changes in your organisation, such as:
- single sign-on settings being added, changed or removed
- API keys being created or revoked
- a member's role being changed
Each event has a level, Info, Warning or Critical, and you can filter the list by level.
Data retention settings
"Retention" means how long a record is kept before it is deleted. Owners and admins can set it for two kinds of record:
- Audit Logs - always kept for at least 3 years, whatever you choose.
- Notifications - your in-app notification history, kept for at least 90 days.
You can choose from 90 days up to 10 years. A setting can make Renewly keep records longer than the minimum, never shorter.
Each setting has an Auto-delete after expiry switch. With it on, records older than your chosen period are deleted. With it off, they are kept. If you never save a setting, the minimums above apply and older records are deleted automatically.
These retention settings do not delete contracts. Account deletion does. Renewly also schedules account deletion after two years without a sign-in or a new contract. You then have 30 days to cancel the deletion. A legal hold can delay it.
Managing compliance settings
Owners and admins find these under Compliance in the Settings menu:
- Settings > Data Retention - choose how long records are kept
- Settings > Security Events - review security-related changes
- Settings > SSO - save your single sign-on details
- Settings > Activity Log - the full record of who did what
Still stuck? Write to the founder; it is really him who answers.
