Trust & compliance
Customers choose Reesure to handle live rent flows. That makes security and compliance non-negotiable — for them, and for us.
Customer data is encrypted in transit and at rest, processed in the European Economic Area, and runs on certified infrastructure (Microsoft Azure, Stripe Payments Europe). Reesure is fully GDPR-compliant. Our own ISO 27001 and ISAE 3402 certifications are on the roadmap.
Scope and data flow
Reesure connects to the customer's existing property management system to import tenants and leases. From there, the rent cycle runs on Reesure: payment collection via Stripe, tenant messaging via MessageBird, and reporting back to the customer.
All processing happens on Microsoft Azure in the European Economic Area, encrypted in transit (TLS 1.2+) and at rest (AES-256). Reesure never holds funds — payouts move from Stripe directly to the customer's bank. Reesure never sees full card or bank-account numbers; Stripe holds those.
Security controls
- PeriodicVulnerability scans
Automated security scans
- PeriodicPenetration test
Third-party assessment
- ContinuousPlatform monitoring
Health and security events
Hosting and data residency. All Customer data is processed and stored within the European Economic Area, on Microsoft Azure.
Encryption. AES-256 at rest. TLS 1.2+ in transit.
Access. Multi-factor authentication required for all administrative access. Role-based access with least-privilege. All administrative access logged and reviewable.
Monitoring and response. 24/7 monitoring of platform health and security events. Automated anomaly detection and API rate-limiting.
Vulnerability management. Quarterly vulnerability scans. Annual external penetration test. Remediation tracked against severity-based SLAs.
Sub-processors. A limited set, listed in the DPA Annex A. Sub-processor changes are notified 30 days in advance. Sub-processors outside the EEA operate under EU Standard Contractual Clauses.
GDPR / AVG. Reesure is fully compliant with the EU General Data Protection Regulation. Legal bases for each processing purpose are documented in the Privacy Policy. Data subject rights are handled within 30 days. Supervisory authority: Dutch Autoriteit Persoonsgegevens (AP).
Infrastructure & Subprocessors
Reesure operates on enterprise-grade cloud infrastructure with industry-leading security certifications.
- Microsoft Azure
Hosting, compute, storage
- ISO 27001
- SOC 2
- ISAE 3402
- ISO 27018
- Stripe Payments Europe
Payment processing, payouts
- PCI DSS L1
- SOC 2 Type 2
- ISO 27001
- MessageBird
Email, SMS, WhatsApp
- ISO 27001
- GDPR
Incidents and reliability
- 48h
Breach notification to affected customers, per DPA §9
- 2h
Notification of material outages in Stripe, banks, or payment networks
- 99%
Monthly uptime target, with service credit if below 97%
Breach notification. If a breach affects customer data, we notify the affected customer without undue delay after becoming aware, and where feasible within 48 hours. We assist customers in fulfilling their own notification obligations to the supervisory authority and to affected data subjects.
Service incidents. Reesure doesn't operate the payment networks, but we monitor them. When Stripe, banks, or payment networks experience a material outage, we notify affected customers by email within 2 hours.
Uptime and service credit. 99% monthly uptime target for the application, excluding planned maintenance. If uptime falls below 97% in a month, Customers may request a 10% credit of that month's Platform fees. Downtime caused by Stripe, banks, payment networks, or messaging providers is excluded. Full SLA in Terms of Service, Annex A.
Reporting a security issue. Email support@reesure.com. We do our best to respond within 1 business day and confirm receipt before triage.
Policies and contracts
Publicly available
- Privacy Policy: what data we process, why, your rights
- Terms of Service: contractual terms and SLA
- Cookie Policy: cookies and trackers on reesure.com
- Data Processing Agreement (DPA): contractual data-protection terms, sub-processor list, security measures
Available on request
- Security overview: architecture and controls summary
- Counter-signable DPA: for procurement processes that require it
Email support@reesure.com for either.
Contact
For anything on this page, email support@reesure.com.