Security Overview
RentThread Security Overview
Last updated: {{LAST_UPDATED_DATE}}
RentThread is designed to keep public apartment discussions separate from private account, residency, Property Alias, moderation, and security information.
Our security program uses safeguards appropriate to the Service, including:
- Restricted access and least privilege
- Multifactor authentication for staff
- Encryption in transit and provider-managed encryption at rest
- Separation of public product data from private identity and moderation data
- Private storage and time-limited access for sensitive assets if those features are enabled
- Application, database, dependency, and authorization testing
- Secret scanning and protected software delivery
- Logging, monitoring, backups, and incident response with limits on personal information in logs
- Staff access and high-risk action auditing
No online service can guarantee absolute security. RentThread does not claim that a Property Alias is untraceable or immune from valid legal process.
Report a security vulnerability
Send a private report to security@rentthread.com with the affected URL or component, steps to reproduce, potential impact, and supporting material. Encrypt sensitive details using the key published at /.well-known/security.txt if available.
Please:
- Avoid accessing, changing, retaining, or sharing another person’s data.
- Use only accounts and synthetic information you control.
- Do not conduct denial-of-service, spam, social engineering, physical attacks, automated high-volume scanning, or actions that impair the Service.
- Stop testing and report immediately if you encounter private data.
- Give us a reasonable opportunity to investigate before public disclosure.
- Do not demand payment or threaten disclosure. RentThread does not offer a public bug bounty unless expressly announced.
RentThread will acknowledge good-faith reports and work to validate and remediate them. Any vulnerability-disclosure safe-harbor language must be approved by counsel and does not authorize conduct that harms users, violates privacy, or exceeds the written scope.
For account compromise, use the account-recovery process and contact security@rentthread.com. For immediate danger, call 911.
Required security.txt
Publish and keep current:
Contact: mailto:security@rentthread.com
Expires: {{SECURITY_TXT_EXPIRATION_ISO}}
Policy: https://rentthread.com/security
Preferred-Languages: en
Canonical: https://rentthread.com/.well-known/security.txt
Do not publish an encryption line until a monitored public key and rotation process exist.