Security & Data Handling
Your contract data is sensitive. Here's exactly how RenewalGuard handles it — with no ambiguity.
We store only what we extract. Your contract documents are deleted the moment AI processing completes.
Zero document retention
Source contract files are read into memory, processed by AI, and discarded immediately. They are never written to permanent storage. There is no mechanism to retrieve your original documents from RenewalGuard.
Metadata-only database
The only data we store is structured metadata: supplier name, dates, notice periods, and contract values. No contract text, clauses, or confidential terms are retained in any form.
Encryption at rest and in transit
All stored metadata is encrypted at rest using AES-256. All data transmitted between your browser and our servers uses TLS 1.3. We do not support non-encrypted connections.
Audit logging
Every upload, view, and deletion is logged with user identity and timestamp. Audit logs are immutable and retained for 12 months, enabling full traceability for compliance purposes.
Infrastructure security
RenewalGuard runs on enterprise cloud infrastructure with network isolation, automated vulnerability scanning, and regular penetration testing. All systems are monitored 24/7.
SOC 2 aligned controls
Our security controls are aligned with SOC 2 Type II principles covering security, availability, and confidentiality. Enterprise customers can request our security documentation.
Additional security policies
Questions about our security posture? Enterprise customers can request full documentation.