Security, privacy and compliance
Your data and your customers' data are valuable. At Rentix, security isn't an option: it's a commitment we take seriously in every line of code and every infrastructure decision.
Here is how we protect your business day in and day out, and why our clients trust us to host their most sensitive data.
100% Canadian hosting
All Rentix data is hosted in Canadian data centers operated by certified providers. No data leaves Canadian soil without your explicit consent.
This location ensures your information remains subject to Canadian and Quebec law, and protects you from extraterritorial access requests that can affect services hosted abroad.
End-to-end encryption
All communications between your browser and our servers are encrypted with TLS 1.3 and HSTS enabled. Your data is also encrypted at rest (AES-256) in our databases and backups.
Sensitive information (passwords, API tokens, payment data) receives additional application-layer encryption and is never accessible in plain text, even by our technical team.
Tenant isolation (multi-tenant)
Every client organization has its own logically isolated workspace through a Row-Level Security (RLS) architecture at the database level. This guarantees that no query, accidental or malicious, can access another client's data.
For clients who require it, we also offer physical isolation with a dedicated database (Enterprise plan).
Law 25 and GDPR compliance
Rentix is fully compliant with Quebec's Law 25 and the European General Data Protection Regulation (GDPR). This includes the right of access, rectification, portability and deletion.
We maintain a record of processing activities, appoint a data protection officer, and notify any incident within the legal timeframe.
Automatic backups and redundancy
Your data is backed up automatically several times a day with a 30-day retention window. Backups are stored in a geographically distinct zone from the primary server, while still remaining in Canada.
In case of a major incident, our RTO (recovery time objective) is 4 hours and our RPO (recovery point objective) is 1 hour. You can also export all your data at any time via the interface or the API.
Access control and auditing
Rentix supports two-factor authentication (2FA) for all users, single sign-on (SSO) for Business and Enterprise plans, and fine-grained role-based permissions.
Every sensitive action is logged in a consultable audit trail: login, price changes, file deletions, customer record access. You know who did what and when.
Monitoring and updates
Our infrastructure is monitored 24/7 by intrusion detection and anomaly detection systems. Security patches are applied within hours of their publication by vendors.
We also run regular penetration tests by external firms, and our code goes through static security analysis before every deployment.
Questions about security?
Our team can provide a detailed security briefing, ideal for your RFPs or IT department review.