Privacy by architecture, not by promise.
Ren sits in the conversations where people actually work, so the privacy boundary has to be built into the system rather than written into a policy. Here is how it works, what we hold, and where it runs — no form required.

Coaching is private. Only the outcome travels.
Ren is built so that private, unstructured workplace conversation never lands in a persistent store without an explicit, user-initiated purpose. PII is masked before it ever reaches the LLM, and conversations inside shared team channels are buffered inside our VPC for up to 72 hours and auto-purged on consumption.
Ren cannot read your direct messages
Ren only sees conversations it has been explicitly added to: channels and multi-party group messages where someone invited it, plus your own direct conversation with Ren. It has no access to direct messages between two people — that is enforced by the permissions Slack and Microsoft Teams grant the app, not by our policy.
Your coaching conversation is yours
The work you do directly with Ren — the message you rewrote, the conversation you were dreading — is not surfaced to your manager or to leadership. Ren coaches you; it does not report on you.
What rolls up
Aggregate outcomes and adoption, not transcripts. Leaders can see whether the practice is actually happening across the org. They do not get a readable feed of what their people said.
What we deliberately don't build
No sentiment scoring of individuals, no productivity surveillance, no ranking people against each other. If a feature would only be useful for monitoring people, it doesn't ship.
The eight answers reviews open with
If you are filling in a vendor security questionnaire, this section should cover most of page one.
- Hosting
- AWS (US)
- Single-region, EKS, multi-AZ
- Encryption
- TLS 1.2+ / AES-256
- In transit & at rest
- Authentication
- SSO / SAML
- Okta, Entra, Google
- Data residency
- US-only
- No cross-region transfer
- LLM providers
- Anthropic + OpenAI
- Zero-retention terms
- PII protection
- Guardrails AI
- Masked before the LLM
- Secrets
- AWS Secrets Manager
- KMS-backed, rotated
- Independent audit
- SOC 2 Type II
- Report available under NDA
Forward these freely
No form, no password. Share them with anyone evaluating Ren.
Sub-processor list
Every third-party service Ren uses to operate the product — purpose, region, data scope, and contract terms.
Data Processing Agreement
The twelve-clause structure of Ren's DPA: SCCs, zero-retention LLM terms, audit rights, breach notification.
Vulnerability Disclosure Policy
How to responsibly report a security issue to our team, with a 90-day coordinated disclosure window.
The reviewer document package
Everything above is public. The detailed materials below are shared with named reviewers, because they carry architecture detail and contract language we don’t publish. Enter your work email and you’re in — we log who accessed the package so we can tell you if something material changes.
- Security & Architecture Brief — architecture, data flows, identity, encryption, and the 12-question ARB FAQ
- Full DD & Procurement Packet — the complete reviewer-ready package
- Executive Summary and Procurement Conversation Starter
- SOC 2 Type II report and penetration test summary, on request under NDA
We typically respond to security questions within one business day. Live ARB walkthroughs available on request.