Reesure

Trust & compliance

Customers choose Reesure to handle live rent flows. That makes security and compliance non-negotiable — for them, and for us.

Customer data is encrypted in transit and at rest, processed in the European Economic Area, and runs on certified infrastructure (Microsoft Azure, Stripe Payments Europe). Reesure is fully GDPR-compliant. Our own ISO 27001 and ISAE 3402 certifications are on the roadmap.

Scope and data flow

Reesure connects to the customer's existing property management system to import tenants and leases. From there, the rent cycle runs on Reesure: payment collection via Stripe, tenant messaging via MessageBird, and reporting back to the customer.

All processing happens on Microsoft Azure in the European Economic Area, encrypted in transit (TLS 1.2+) and at rest (AES-256). Reesure never holds funds — payouts move from Stripe directly to the customer's bank. Reesure never sees full card or bank-account numbers; Stripe holds those.

PMS or ERP systems

Tenants, leases

Accounting

Ledger, payouts

Reesure
Azure · EEA

Application, database, encryption, MFA, RBAC

Stripe

Payment processing

MessageBird

Email, SMS, WhatsApp

All processing within the EEA; limited US sub-processors under EU SCCs.

Security controls

  • Periodic
    Vulnerability scans

    Automated security scans

  • Periodic
    Penetration test

    Third-party assessment

  • Continuous
    Platform monitoring

    Health and security events

Hosting and data residency. All Customer data is processed and stored within the European Economic Area, on Microsoft Azure.

Encryption. AES-256 at rest. TLS 1.2+ in transit.

Access. Multi-factor authentication required for all administrative access. Role-based access with least-privilege. All administrative access logged and reviewable.

Monitoring and response. 24/7 monitoring of platform health and security events. Automated anomaly detection and API rate-limiting.

Vulnerability management. Quarterly vulnerability scans. Annual external penetration test. Remediation tracked against severity-based SLAs.

Sub-processors. A limited set, listed in the DPA Annex A. Sub-processor changes are notified 30 days in advance. Sub-processors outside the EEA operate under EU Standard Contractual Clauses.

GDPR / AVG. Reesure is fully compliant with the EU General Data Protection Regulation. Legal bases for each processing purpose are documented in the Privacy Policy. Data subject rights are handled within 30 days. Supervisory authority: Dutch Autoriteit Persoonsgegevens (AP).

Infrastructure & Subprocessors

Reesure operates on enterprise-grade cloud infrastructure with industry-leading security certifications.

  • Microsoft Azure

    Hosting, compute, storage

    • ISO 27001
    • SOC 2
    • ISAE 3402
    • ISO 27018
  • Stripe Payments Europe

    Payment processing, payouts

    • PCI DSS L1
    • SOC 2 Type 2
    • ISO 27001
  • MessageBird

    Email, SMS, WhatsApp

    • ISO 27001
    • GDPR

Incidents and reliability

  • 48h

    Breach notification to affected customers, per DPA §9

  • 2h

    Notification of material outages in Stripe, banks, or payment networks

  • 99%

    Monthly uptime target, with service credit if below 97%

Breach notification. If a breach affects customer data, we notify the affected customer without undue delay after becoming aware, and where feasible within 48 hours. We assist customers in fulfilling their own notification obligations to the supervisory authority and to affected data subjects.

Service incidents. Reesure doesn't operate the payment networks, but we monitor them. When Stripe, banks, or payment networks experience a material outage, we notify affected customers by email within 2 hours.

Uptime and service credit. 99% monthly uptime target for the application, excluding planned maintenance. If uptime falls below 97% in a month, Customers may request a 10% credit of that month's Platform fees. Downtime caused by Stripe, banks, payment networks, or messaging providers is excluded. Full SLA in Terms of Service, Annex A.

Reporting a security issue. Email support@reesure.com. We do our best to respond within 1 business day and confirm receipt before triage.

Policies and contracts

Publicly available

Available on request

  • Security overview: architecture and controls summary
  • Counter-signable DPA: for procurement processes that require it

Email support@reesure.com for either.

Contact

For anything on this page, email support@reesure.com.