Rendrly is built to see your business, not your customers. This page describes how the product is designed to protect your data — grounded in the compliance approach we're building toward ahead of launch.
The single most effective security control is not collecting sensitive data in the first place.
Rendrly is designed to receive only tokenized or truncated transaction data — the BIN, last four digits, and card brand. The full primary account number (PAN) never reaches us.
That limited data is all we need to detect card mix, spot downgrades, and analyze your effective rate — without ever holding information that could identify a cardholder.
Software that touches cardholder data becomes a PCI service provider. We designed around that reality from the start.
Because handling cardholder data brings PCI DSS obligations, Rendrly's architecture minimizes what data enters our systems, keeping the compliance footprint as small as possible.
A formal PCI scoping review with a Qualified Security Assessor (QSA) is planned before launch. This page reflects design intent, not a completed certification.
AI never touches cardholder or individual-customer data.
Insights are generated from merchant-level business totals — your rates, fees, and category mix. No cardholder or individual-customer data is ever sent to the model.
Every figure the model reports is validated against pre-computed facts, so the numbers you read reflect your real data — not a language model's estimate.
Rendrly is an analysis layer, not a processor or a bank.
Rendrly analyzes the settlement data you already have. It reads and reports — it does not initiate, capture, or alter transactions.
Your money continues to flow through your existing processor and bank exactly as it does today. Rendrly never takes possession of or moves merchant funds.
Connecting QuickBooks Online is designed to be safe and reversible.
Each merchant authorizes QuickBooks Online through OAuth. You grant access, and you can revoke it at any time from your accounting account.
Sync runs one way — from settlement into your books — on a daily cadence. Access tokens are handled securely and are never exposed in the product.
Security is a shared effort. We welcome reports from the community.
If you believe you've found a security issue, please email security@rendrly.app Placeholder with the details. We'll acknowledge your report and work with you on a fix.
We support good-faith research and will not pursue action against researchers who disclose responsibly and avoid harming merchants or their data.
This page describes Rendrly's security and compliance design approach. It is not a certification, warranty, or legal advice. PCI scoping and payments-counsel reviews are in progress ahead of launch.
See how Rendrly finds your savings without ever seeing your customers' card data.