Security incidents
When we notify you, and how to report one in.
Our incident-notification process in plain English — the short version is: we say something, we say what to do, we do not minimise, and we do not bury a substantive update.
When we notify you
If a security incident affects your account, your data, or your guests’ data, we notify you without undue delay after we have enough confirmed information to act. We do not wait for a perfect timeline before speaking with affected users.
What we send
A clear written notice: what happened, what categories of data were involved, what we have already done, and what we recommend you do. The notice goes to the account owner’s registered contact; security contact addresses on file are CC’d.
What we will not do
We do not minimise the incident. We do not bury a substantive update behind a marketing note. Vendor-side junk ("cyber event at a partner") is not a substitute for a real status update.
How to report a vulnerability
Email security@rentaraai.com with a clear subject line ("Security report" + short descriptor), the affected endpoint or behaviour, reproduction steps, and any proof-of-concept material. We acknowledge within two business days and aim to give a real engineering response within five.
Report a vulnerability
Found something we should know about?
Send a clear report: affected endpoint or behaviour, reproduction steps, proof-of-concept material. We acknowledge within two business days and respond with an engineering assessment within five.
Do not include customer data in your report. Reproductions against your own tenant are fine; reproductions involving real guest data are not.
Business identity
Who you’re contracting with
The contracting entity for RentaraAI is Steadwright LLC, an Indiana limited liability company, with its registered office at 2120 W Washington St, Suite 200, Indianapolis, IN 46222, United States. The entity governs itself under the laws of the State of Indiana, United States.
Data controller
Steadwright LLC (the entity above) decides why and how your personal data is processed when you use RentaraAI.
Third-party subprocessors: OpenAI — API, Polsia, Inc. — R2 object storage, Polsia, Inc. — Email proxy, Stripe, Inc., Render (hosting) + Cloudflare (edge).
Internal components (not shared with any third party): better-auth (local Postgres account store). Full table — categories, locations, retention, links — on /subprocessors.
For the broader security posture, see /security.
Effective: 2026-09-11 · v2026-08-06