Trust & Security

Privacy by architecture, not by promise.

Ren sits in the conversations where people actually work, so the privacy boundary has to be built into the system rather than written into a policy. Here is how it works, what we hold, and where it runs — no form required.

AICPA SOC 2 Type II attestation badge
The privacy boundary

Coaching is private. Only the outcome travels.

Ren is built so that private, unstructured workplace conversation never lands in a persistent store without an explicit, user-initiated purpose. PII is masked before it ever reaches the LLM, and conversations inside shared team channels are buffered inside our VPC for up to 72 hours and auto-purged on consumption.

Ren cannot read your direct messages

Ren only sees conversations it has been explicitly added to: channels and multi-party group messages where someone invited it, plus your own direct conversation with Ren. It has no access to direct messages between two people — that is enforced by the permissions Slack and Microsoft Teams grant the app, not by our policy.

Your coaching conversation is yours

The work you do directly with Ren — the message you rewrote, the conversation you were dreading — is not surfaced to your manager or to leadership. Ren coaches you; it does not report on you.

What rolls up

Aggregate outcomes and adoption, not transcripts. Leaders can see whether the practice is actually happening across the org. They do not get a readable feed of what their people said.

What we deliberately don't build

No sentiment scoring of individuals, no productivity surveillance, no ranking people against each other. If a feature would only be useful for monitoring people, it doesn't ship.

At a glance

The eight answers reviews open with

If you are filling in a vendor security questionnaire, this section should cover most of page one.

Hosting
AWS (US)
Single-region, EKS, multi-AZ
Encryption
TLS 1.2+ / AES-256
In transit & at rest
Authentication
SSO / SAML
Okta, Entra, Google
Data residency
US-only
No cross-region transfer
LLM providers
Anthropic + OpenAI
Zero-retention terms
PII protection
Guardrails AI
Masked before the LLM
Secrets
AWS Secrets Manager
KMS-backed, rotated
Independent audit
SOC 2 Type II
Report available under NDA
For a formal review

The reviewer document package

Everything above is public. The detailed materials below are shared with named reviewers, because they carry architecture detail and contract language we don’t publish. Enter your work email and you’re in — we log who accessed the package so we can tell you if something material changes.

What’s inside
  • Security & Architecture Brief — architecture, data flows, identity, encryption, and the 12-question ARB FAQ
  • Full DD & Procurement Packet — the complete reviewer-ready package
  • Executive Summary and Procurement Conversation Starter
  • SOC 2 Type II report and penetration test summary, on request under NDA

We typically respond to security questions within one business day. Live ARB walkthroughs available on request.

Ren logo

Start free

Free for up to 4 people. No credit card. Create your account, then connect Slack in a couple of clicks.

or use your email

Your conversations with Ren are always private.