Security is part of the trust product.

Landlords and tenants trust Tensu with leases, rent records, notices, documents and inspection evidence. The platform is built around scoped access, backend-enforced authorization and evidence integrity, not just a privacy policy promise.

How we protect your data

Practices, not promises.

Encryption in transit and at rest

All traffic between the app, dashboard and backend runs over TLS. Stored records and files are encrypted at rest by our database and storage providers.

Property-scoped access control

Every record belongs to a property and a role. Tenants and landlords only ever see the records their role and active tenancy actually grant them access to.

Signed, time-limited file access

Documents, photos and inspection media are served through short-lived signed URLs rather than public links, so a leaked link doesn't mean a leaked document.

Authorization at the backend, not the client

The mobile app and dashboard never talk to the database directly. A dedicated backend API enforces every authorization check before any record is read or written.

Audit-oriented history

Confirmations, edits and status changes are kept as part of the tenancy timeline, so important actions stay traceable instead of silently overwritten.

Independent identity verification

Rental Passport verification is handled by a dedicated identity verification provider. Tensu never stores your raw ID document beyond what's needed for that check.

Infrastructure

The providers behind the platform.

We rely on a small set of specialized providers rather than building everything in-house. Each one only receives the data it needs to do its job. The same list is published in full in our Privacy Policy.

Responsible disclosure

Found a vulnerability?

If you believe you've found a security issue in Tensu, we want to know before anyone else does. Email us with enough detail to reproduce it, and we'll acknowledge your report and keep you updated as we investigate and fix it.

  • We won't pursue legal action against good-faith security research.
  • Please avoid accessing or modifying data that isn't yours while testing.
  • Give us a reasonable window to fix an issue before any public disclosure.

Reach the team at security@tensu.app.