Your data stays yours.

Rendrly is built to see your business, not your customers. This page describes how the product is designed to protect your data — grounded in the compliance approach we're building toward ahead of launch.

Data minimization

We're designed never to see the full card number.

The single most effective security control is not collecting sensitive data in the first place.

Tokenized, truncated data only

Rendrly is designed to receive only tokenized or truncated transaction data — the BIN, last four digits, and card brand. The full primary account number (PAN) never reaches us.

Enough to help, not to expose

That limited data is all we need to detect card mix, spot downgrades, and analyze your effective rate — without ever holding information that could identify a cardholder.

PCI DSS approach

Scope minimized from day one.

Software that touches cardholder data becomes a PCI service provider. We designed around that reality from the start.

Architected for minimal scope

Because handling cardholder data brings PCI DSS obligations, Rendrly's architecture minimizes what data enters our systems, keeping the compliance footprint as small as possible.

Formal QSA review planned

A formal PCI scoping review with a Qualified Security Assessor (QSA) is planned before launch. This page reflects design intent, not a completed certification.

Aggregate-only AI

Insights run on business totals, never on people.

AI never touches cardholder or individual-customer data.

Merchant-level totals only

Insights are generated from merchant-level business totals — your rates, fees, and category mix. No cardholder or individual-customer data is ever sent to the model.

Validated against facts

Every figure the model reports is validated against pre-computed facts, so the numbers you read reflect your real data — not a language model's estimate.

Read-only & funds

We analyze your data. We never move your money.

Rendrly is an analysis layer, not a processor or a bank.

Read-only by design

Rendrly analyzes the settlement data you already have. It reads and reports — it does not initiate, capture, or alter transactions.

Never takes possession of funds

Your money continues to flow through your existing processor and bank exactly as it does today. Rendrly never takes possession of or moves merchant funds.

Accounting-sync security

Secure, one-way sync to your books.

Connecting QuickBooks Online is designed to be safe and reversible.

Per-merchant OAuth

Each merchant authorizes QuickBooks Online through OAuth. You grant access, and you can revoke it at any time from your accounting account.

One-way daily sync, tokens secured

Sync runs one way — from settlement into your books — on a daily cadence. Access tokens are handled securely and are never exposed in the product.

Responsible disclosure

Found something? Tell us.

Security is a shared effort. We welcome reports from the community.

Report a vulnerability

If you believe you've found a security issue, please email security@rendrly.app Placeholder with the details. We'll acknowledge your report and work with you on a fix.

Good-faith research welcome

We support good-faith research and will not pursue action against researchers who disclose responsibly and avoid harming merchants or their data.

A note on this page

This page describes Rendrly's security and compliance design approach. It is not a certification, warranty, or legal advice. PCI scoping and payments-counsel reviews are in progress ahead of launch.

Built to earn your trust.

See how Rendrly finds your savings without ever seeing your customers' card data.