Security
Protecting trust by design.
Last updated July 28, 2026. RenoMe applies practical controls proportionate to the information and services we operate.
Our baseline
RenoMe follows a risk-based approach informed by the Canadian Centre for Cyber Security’s baseline controls for small and medium organizations.
- Public forms store submissions in managed server-side storage, not in the visitor’s browser.
- Prototype administration is not published. Administrative access requires a separate, authenticated system before it can go live.
- Access is limited by role, important accounts use multi-factor authentication where available, and access is removed when no longer required.
- Connections use HTTPS. Systems, dependencies, devices, and security tools are kept current.
- Essential information is backed up and recovery procedures are tested in proportion to operational risk.
- We maintain incident-response and escalation procedures and review service providers before entrusting them with information.
What we will never ask for here
RenoMe will not ask you through a public website form for passwords, one-time security codes, full payment-card numbers, banking credentials, or copies of identity or immigration documents.
Report a concern
If you believe you found a security weakness or received a suspicious message claiming to be from RenoMe, email hello@renome.io with “Security” in the subject. Include the affected page, what you observed, and how we can contact you.
Do not access other people’s data, disrupt services, use automated high-volume testing, or publicly disclose a suspected vulnerability before we have had a reasonable opportunity to investigate.
Response
We will acknowledge credible reports, assess severity, contain and correct confirmed issues, preserve appropriate records, and notify affected people or authorities when required. We cannot promise a reward, but we appreciate responsible reports made in good faith.
Reference guidance: Canadian Centre for Cyber Security baseline controls.