We handle your most sensitive financial data — here's exactly how we protect it.
Where managed: Cloudflare — the world's largest edge network. Every request to wereportyourrent.com is automatically encrypted via TLS 1.3.
How it works: Cloudflare terminates HTTPS at the edge (200+ global locations) and forwards traffic to our Workers over Cloudflare's own secure backbone. There is no plain HTTP path. HTTP requests are automatically redirected (301) to HTTPS.
HSTS Header: We send Strict-Transport-Security: max-age=31536000; includeSubDomains; preload — this tells browsers to always use HTTPS for our domain, even if you type http://.
SSL Certificate: Automatically issued and renewed by Cloudflare. Zero manual management. Covers wereportyourrent.com and *.wereportyourrent.com.
Your custom domain: Point your DNS to Cloudflare, enable the orange cloud (proxy), and HTTPS is live in minutes — no certificate purchase needed.
What it is: The FCRA (15 U.S.C. § 1681) is a federal law governing how consumer credit information can be collected, accessed, and reported. Any company that reports to or obtains data from credit bureaus must comply.
What we do:
consent_records table with timestamps, IP address, and consent version.audit_log table. Rows are never updated or deleted.Bureau credentialing: Powered by Array.com, which holds established bureau relationships and handles all bureau credentialing, dispute management, and FCRA-compliant reporting workflows.
What it is: PCI DSS v4.0 (enforced March 2025) is the security standard for any business that processes, stores, or transmits payment card data.
How we handle it:
js.stripe.com), preventing card-skimming script injection (PCI DSS 6.4.3).User account data (name, email, phone, DOB)
Last 4 SSN hashed with SHA-256
Lease metadata (file location, dates, status)
Credit snapshots from Array.com
Audit logs for every sensitive action
Full SSN or social security numbers
Credit card numbers, CVVs, or PINs
Full credit reports in plain text
Plaintext passwords (bcrypt only)
Lease file content (stored in R2, not DB)
Cloudflare D1 (SQLite) — structured data
Cloudflare R2 — lease document files
Cloudflare KV — session caching
All within Cloudflare's SOC 2 Type II certified infrastructure
Row-level access control via user IDs
Admin routes protected by JWT auth
Rate limiting on all API endpoints
Parameterised queries only (no raw SQL)
Input sanitisation on all POST endpoints
Our entire application runs on Cloudflare Pages + Workers — this is not a traditional server. Here's what that means for security:
Cloudflare automatically absorbs and mitigates DDoS attacks at the network layer — our application never sees malicious traffic.
Cloudflare's Workers run in an isolated V8 sandbox. No shared server resources. No lateral movement between tenants possible.
Requests are served from the nearest Cloudflare data center — faster responses and no single point of failure.
Cloudflare's Web Application Firewall blocks SQL injection, XSS, and common attack patterns before they reach our code.
Cloudflare Bot Management filters automated attacks, credential stuffing, and scraping attempts.
API keys and secrets are stored as Cloudflare encrypted secrets, not environment files. Never on disk.
FCRA Compliant
PCI DSS via Stripe
HTTPS/TLS Everywhere
HSTS + CSP Headers
Rate Limiting
Input Sanitisation
Audit Logging
SSN Hashing
SOC 2 Type I Audit
Penetration Testing
Formal Incident Response Plan
CCPA Privacy Controls
Multi-Factor Authentication
Admin IP Allowlisting
SOC 2 Type II
ISO 27001 Consideration
State Money Transmitter Review
Consumer Financial Protection (CFPB)
FTC Safeguards Rule Alignment
Rent Credit Assistant
Online — replies instantly