Trust & security

Built to be examined.

Renny exists because a record that can be edited is not evidence. Everything on this page follows from that.

Nothing is ever deleted

A hard delete is refused on every business table. Retiring a record means recording who did it, when, and why — and the row stays. Retired records also leave the everyday lists and exports, so nobody keeps seeing something they thought they removed.

Two independent records

One log of what people did, hash-chained so a removed or altered entry breaks the chain visibly. A second, written by the database itself, of what actually changed row by row — independent of whether the application remembered to log anything.

Signatures that mean something

Each signature records the exact document presented, its fingerprint, the time, the network address, and the authentication method. The signing party is taken from the session, so no party can sign on another’s behalf.

Access can be withdrawn

Permissions carry a withdrawal date and a mandatory reason, and the grant stays on the record. “Were they authorized on the day they signed?” remains answerable after they have left the company.

Scoped by design

Every credential — person or machine — reaches only its own organization’s records. One lender cannot see another lender’s book, and there is no administrative view that quietly bypasses this.

Ledger integrity

The money record is append-only and self-balancing. It records what Renny was told moved, for reconciliation — not what Renny moved, because Renny moves nothing.

Nothing is destroyed

Records are superseded, never overwritten

“Delete” in Renny marks a record retired, records who retired it and why, and removes it from lists and reports. The row stays. An agreement is never edited in place either — changing it writes a new version and keeps the old one.

That is what makes “what did the borrower see when they signed?” answerable years later — including when the answer is not the one anybody wanted.

Each version keeps its own fingerprint, so the scope a party attested to can be produced exactly as they saw it.

Regulators and auditors

Examiner access is a feature, not a fire drill

An oversight grant is scoped to one program and one date range, is read-only, and expires on its own. The examiner’s own reading is logged as well.

Government and auditor roles are part of the platform rather than a report someone assembles the week an examination is announced.

  • Renny grants an examiner or auditor access, with an expiry
  • Each lender holds a switch and may withhold its own records
  • Correspondence runs in-platform, and a sent message is final
  • Every access event is recorded — including the examiner’s own
  • Everything is readable through the same scoped interface a person uses

Withheld is not the same as empty

A lender that withholds still appears on the examiner’s list, marked as withheld.

If switching access off removed you from the list entirely, refusing to cooperate would look identical to having nothing to hide — and no regulator would accept a system that made those two indistinguishable.

Restoring access reveals the period that was dark rather than quietly closing it.

Where we are, stated plainly

A gap you discover after signing costs more than one you were told about.

AreaStatus
Access control and auditLive. Roles, scoping, withdrawal, hash-chained event log, and an independent row-level change log.
EncryptionLive. TLS in transit; managed database encryption at rest. Database access is firewalled to the application.
Evidence captureLive through the web application. Trusted capture — where a photograph carries cryptographic proof of the device, time, and place it was taken — is on the roadmap and needs a native mobile application.
Independent verification at onboardingLicence verification is live. Third-party business verification, insurance validation, and fraud screening are on the roadmap and depend on vendor selection.
SOC 2On the roadmap. It is an audit engagement rather than a feature, and we will not claim it before it is done.
Penetration testingPlanned before general availability. We will share the report and remediation status with prospective lenders under NDA.

If your security review needs a questionnaire completed, send it. We would rather answer it honestly early than discover a blocker late.

Questions we get asked

Does Renny ever hold or move our money?

No. There is no escrow account, no trust account, and no balance held on your behalf. Renny issues an authorization; you disburse on your own rails. That is a deliberate boundary, not a stage of development — it removes money transmitter analysis, commingling questions, and any exposure to funds in flight if we failed.

Who owns the data?

You do. Your records are yours, exportable in full at any time, and scoped so that no other lender can reach them. We will put retention, export, and deletion-on-exit terms in writing before you sign anything — noting that “deletion” inside the platform means retirement with a reason, because an evidence system that can erase its own history is not one.

What happens to our record if Renny goes away?

A fair question to ask a young company. Your data is exportable in full at any time, in formats you can keep and read without us. We will agree an escrow or wind-down arrangement as part of contracting, and we would rather you raise it in the first meeting than the last.

Can a Renny employee change our records?

Not invisibly, and not silently. Every change is attributed and recorded in two independent logs, and the destructive operations are refused outright by the database rather than restricted by policy. Support actions appear in your record as actions taken by a named Renny account.

Does this slow our contractors down?

It should not, and if it does the control will be routed around, which defeats the purpose. Draws are requested against a scope already agreed rather than re-typed, evidence is captured on the device that took the photograph, and training can be read rather than watched. See For contractors.

How does this interact with our existing compliance program?

Renny produces evidence; your program decides what to do with it. Nothing here replaces your policies, your complaint handling obligations, or your regulator relationships. It gives those things a factual record to stand on.

Compliance & standards

Where we stand, with the status attached

We do not display a certification we do not hold. Each item below says whether it is implemented today or on the roadmap, and we will complete your security questionnaire against the same list.

SOC 2 Type IIAudit planned
ISO 27001Roadmap
CFPB-aligned controlsBuilt in
GLBA safeguardsImplemented
ESIGN & UETAImplemented
WCAG 2.1 AADesigned to

Renny is a technology provider, not a lender, broker or money transmitter. Read the full trust and security position.

Send us your security questionnaire.

We will complete it honestly, including the parts that are still on the roadmap.