A summary of the controls we have in place today, the work that is in flight, and how to reach our team about a security question or vulnerability report. We update this page within 30 days of any material change to our posture.
A four-phase roadmap. Phase 1 is in flight today; subsequent phases are sequenced over the next 18 to 24 months.
HIPAA BAA available on request for customers handling Protected Health Information. CCPA / CPRA: we honor data subject requests within 45 days. Email privacy@renovaagentinc.com. GDPR: Data Processing Agreement available on request.
We maintain a documented incident response plan. In the event of a confirmed security incident affecting your data, we will notify affected customers within 72 hours and provide regular updates until resolution. Annual tabletop exercises verify the plan is current and effective.
Our current list of subprocessors is published at renovaagentinc.com/subprocessors. We provide 30-day advance notice of any material changes to this list. To receive change notices, email subscribe@renovaagentinc.com.
If you discover a security vulnerability or have concerns about our security posture, please email us. We respond to confirmed vulnerability reports within 48 hours and work with researchers in good faith. We do not currently offer a bug bounty program but may launch one in the future.
security@renovaagentinc.comEnterprise prospects can request the following under a mutual NDA by emailing security@renovaagentinc.com:
Email security@renovaagentinc.com to request attestation reports, insurance certificates, or internal policies under a mutual NDA.