rentspree logo
Products
Tenant screeningPaymentsRental applicationLease agreementsRent estimateMarketing toolsRenters insuranceLandlord insuranceEnterprise API integration
Who we serve
AgentsLandlordsRentersProperty managers
Enterprise
Enterprise Solutions
MLS
PropTech
Brokerage
REALTOR® Associations
Pricing
Resources
Free coursesBlogCalculatorsHelp centerGet a demoContact us
Book a demo
Log inSign up for free
Three colleagues in an office with large windows, one seated at a laptop labeled RentSpree.

Responsible Disclosure process and limitations

Effective date: March 05, 2026

Vulnerability Reporting

The RentSpree Security team takes security findings extremely seriously. We care deeply about the security of our products and the data that they protect. We investigate every reported security vulnerability and take action to remediate and/or mitigate all issues that we encounter.

‍

RentSpree encourages responsible security research on our services and products. When reporting a potential vulnerability to RentSpree, please include a detailed description of the vulnerability, targets, steps, artifacts (such as web requests, responses and screen captures) in your report.

‍

RentSpree does not accept the vulnerabilities listed below. Please review the responsible disclosure limitations before reporting vulnerabilities to us.

‍

If you believe you’ve identified a security issue, please contact us at security@rentspree.com.

‍

Responsible Disclosure Limitations

RentSpree does not have a formal bug bounty program and we do not currently pay for reported issues, however we welcome submissions and we take action to resolve security issues that are submitted to us in a very timely manner. 

‍

RentSpree considers some vulnerabilities as out of scope.

These include but are not limited to:
  • Unvalidated LLM-generated findings
  • Low Severity Clickjacking Vulnerabilities
  • Missing SPF/DKIM/DMARC policies
  • Display of Organization IDs during login flow
  • User enumeration/brute forcing
  • Automated Scans report (without an exploitable PoC)
  • Content Spoofing Vulnerabilities
  • Denial of Service (DoS)
  • Issues present only in older versions of browsers or plugins
  • Low Impact CSRF issues, including but not limited to: Login and Logout CSRF
  • Missing Rate Limiting Protections (unless corresponding to authentication flow)
  • Missing Security Headers and Cookie Flags, which can’t be exploited by themselves ( for example Strict-Transport-Security, HTTPOnly)
  • Social engineering and phishing attacks
  • Spam e-mail (missing rate limiting protections)
  • TLS/SSL vulnerabilities related to configuration, version, weak ciphers (without a working exploit)
  • Use of a vulnerable 3rd party library/code snippet (without providing an exploitable scenario)
  • Vulnerabilities exploitable only on Unsupported and Outdated Browser, Frameworks and Platforms
  • Weak password
  • Any other submission assessed to be of low/no risk or impact
When using an LLM to generate reports, use this prompt:

“As a security expert who has performed thousands of web application assessments, ensure findings are valid, responses and examples fully reflect the issue it describes, and report findings with as short a description as possible including location, payload, impact, and reproduction steps. Do not provide additional analysis. ”

rentspree logo
Stay up to date on the latest features and releases by joining our newsletter.
By subscribing you agree to comply with our Privacy Policy and provide consent to receive updates from our company.
SOC II Compliance logo
Security
SOC2 Type II Certified
Company
About UsReviewsCareersContact us
Who We Serve
Real Estate AgentsLandlordsProperty ManagersRentersEnterprise
Resources
Help CenterCalculatorsBlogRENEWMedia hub
Products
Tenant ScreeningPaymentsRental ApplicationLease AgreementsMarketing ToolsRent EstimateRenters InsuranceLandlord InsuranceEnterprise API IntegrationLandlord Insurance
Follow Us
Facebook
Instagram
LinkedIn
YouTube
© 2026 RentSpree. All rights reserved.
Privacy PolicyTerms of ServiceAdditional Legal TermsBanking TermsCookies Settings
* RentSpree is a financial technology company and is not a bank. Banking services provided by i3 Bank, Member FDIC. FDIC Pass-Through, Insurance Eligible banking services provided by i3 Bank, Member FDIC. Certain conditions must be satisfied for pass-through deposit insurance coverage to apply. The RentSpree Visa debit card is issued by i3 Bank, Member FDIC, pursuant to a license from Visa U.S.A. Inc. and may be used anywhere Visa cards are accepted. Your deposits qualify for up to $3,000,000 in FDIC insurance coverage when placed at program banks in the i3 Bank deposit sweep program. Your deposits at each program bank become eligible for FDIC insurance up to $250,000, inclusive of any other deposits you may already hold at the bank in the same ownership capacity. You can access the terms and conditions of the sweep program at https://i3.bank/sweepdisclosure/and a list of program banks at https://i3.bank/programbanks/. Pass-through insurance coverage is subject to conditions.

** Annual Percentage Yield (APY) is variable and subject to change after account opening. Rate is compounded monthly and credited monthly. Total balances less than $10,000 earn up to 1.00% APY. Total balances between $10,000 and $49,999 earn up to 1.875%. Total balances of $50,000 or more earn 2.5% APY.