Founder draft — attorney review required. This document is a working draft and has not been reviewed by counsel. It may change before RentThread launches publicly.

Security Overview

RentThread Security Overview

Last updated: {{LAST_UPDATED_DATE}}

RentThread is designed to keep public apartment discussions separate from private account, residency, Property Alias, moderation, and security information.

Our security program uses safeguards appropriate to the Service, including:

  • Restricted access and least privilege
  • Multifactor authentication for staff
  • Encryption in transit and provider-managed encryption at rest
  • Separation of public product data from private identity and moderation data
  • Private storage and time-limited access for sensitive assets if those features are enabled
  • Application, database, dependency, and authorization testing
  • Secret scanning and protected software delivery
  • Logging, monitoring, backups, and incident response with limits on personal information in logs
  • Staff access and high-risk action auditing

No online service can guarantee absolute security. RentThread does not claim that a Property Alias is untraceable or immune from valid legal process.

Report a security vulnerability

Send a private report to security@rentthread.com with the affected URL or component, steps to reproduce, potential impact, and supporting material. Encrypt sensitive details using the key published at /.well-known/security.txt if available.

Please:

  • Avoid accessing, changing, retaining, or sharing another person’s data.
  • Use only accounts and synthetic information you control.
  • Do not conduct denial-of-service, spam, social engineering, physical attacks, automated high-volume scanning, or actions that impair the Service.
  • Stop testing and report immediately if you encounter private data.
  • Give us a reasonable opportunity to investigate before public disclosure.
  • Do not demand payment or threaten disclosure. RentThread does not offer a public bug bounty unless expressly announced.

RentThread will acknowledge good-faith reports and work to validate and remediate them. Any vulnerability-disclosure safe-harbor language must be approved by counsel and does not authorize conduct that harms users, violates privacy, or exceeds the written scope.

For account compromise, use the account-recovery process and contact security@rentthread.com. For immediate danger, call 911.

Required security.txt

Publish and keep current:

Contact: mailto:security@rentthread.com
Expires: {{SECURITY_TXT_EXPIRATION_ISO}}
Policy: https://rentthread.com/security
Preferred-Languages: en
Canonical: https://rentthread.com/.well-known/security.txt

Do not publish an encryption line until a monitored public key and rotation process exist.