Skip to main content
Security

Your contracts are sensitive. We treat them that way.

Renewal Pilot is built with security at every layer - from authentication to data storage to access control. Your contract data is protected by the same standards used by financial institutions.

Security

Built-in protection at every layer.

MFA on every account

TOTP-based multi-factor authentication available on every plan. Aligned with NIST 800-63B guidelines. No extra charge.

Encryption in transit and at rest

All data is encrypted using TLS 1.2+ in transit and AES-256 at rest. Your contracts never travel or sit unprotected.

Granular role-based permissions

Five roles - Viewer, Member, Admin, Owner, and Super Admin - each with specific permissions. Control who can see, edit, and manage contracts.

Every action tracked

Full audit trail with timestamps and user attribution on Team and Business plans. Know who did what and when.

Rate limiting and abuse protection

API and authentication endpoints are rate-limited to prevent brute force attacks and abuse. Automatic lockout after repeated failures.

CSRF and session protection

Cross-site request forgery protection on every form and API call. Secure session management with configurable timeouts.

How we handle your data.

Your contract files are stored securely and never shared with third parties

AI processing uses Anthropic Claude - your data is not used to train AI models

You can export your data at any time on Professional and Enterprise plans

After cancellation, you get 30 days of read-only access, then data is archived

We do not display ads or sell user data

Questions about security?

Reach out to our team. We are happy to discuss our security practices in detail.

Contact Us