Legal
Security
Last updated June 15, 2026
ThriveRent handles sensitive resident and billing data for multiple operators, so security and tenant isolation are built into the platform’s architecture. This page describes the safeguards in place today.
Authentication & access
- Authentication is handled by Clerk, with role-based permissions enforced server-side.
- Access follows a deny-by-default model: users only reach data for the organizations and facilities they are granted.
- Tenant isolation is enforced at the database layer with row-level security, not just in application code.
Data protection
- All traffic is encrypted in transit (TLS).
- Data is hosted on managed infrastructure (Vercel and Supabase) with encryption at rest.
- Payment credentials are handled by our payment processor (Stripe); we do not store full card or bank-account numbers.
Auditability
- Charges, corrections, refunds, and exports are recorded with who, when, and why.
- The audit trail is designed to support month-end reconciliation and external review.
Compliance
We align our practices with recognized security frameworks and are continuing to mature our formal compliance program. We do not claim a completed SOC 2 examination on this page; if you need current compliance documentation or have a vendor-security questionnaire, request it through the Help Center and we will share what is available, under NDA where appropriate.
Reporting a vulnerability
If you believe you’ve found a security issue, please contact us through the Help Center so we can investigate promptly.
Questions about this document? Visit the Help Center or reach your facility administrator.