Skip to main content
Wrenbase

Trust at Wrenbase

Built to be trusted with your money.

Wrenbase is built for businesses that handle money seriously, with each business's data kept separate, encrypted infrastructure, passwordless sign-in, screening on the bills that come in, and payments handled by Stripe. These are commitments we hold ourselves to, not a checklist.

Tenant isolationEncryptionPasswordless authSubmission screeningSanctions screeningStripe-hosted

The promise

Wrenbase is built on commitments that ship the day you sign up. Every claim below is enforced in the product itself, on every request, rather than living only in a compliance document.

Tenant isolation

Your data never touches another tenant's.

Each business's data is isolated at the deepest layer, so one business's records are physically walled off from another's. An employee working in one account cannot reach another account's data through any path.

  • Every database query carries your account as a filter. There is no path that returns another customer's rows.
  • Shared records (an invoice between you and a vendor) show each side only their own view, never both at once.
  • Wrenbase staff don't access your data in the normal course of running the product. If you request support that requires it, we'll ask first.

Tenant A

Invoice INV-1042

Customer: Meridian Aerospace

Payment $2,750

No crossing

Tenant B

Invoice INV-2057

Customer: Müller GmbH

Payment €3,200

Isolation enforced at the deepest layer

Commitments

Commitments that run on every request.

Sanctions screening

Sanctioned jurisdictions blocked at the door.

Wrenbase screens Invoice Me submissions and account signups for sanctions compliance. Anything tied to a comprehensively sanctioned jurisdiction is stopped before it reaches your inbox, so you stay on the right side of the rules.

Payments

Stripe-hosted. Never on our servers.

Wrenbase never touches your or your customers' card numbers or bank account details. All payments flow through Stripe-hosted surfaces. Wrenbase stores references and metadata, not payment instruments.

Encryption

In transit and at rest, end to end.

All connections use TLS. All data at rest is encrypted on AWS-managed infrastructure. The access tokens for services you connect are encrypted separately, so they're never stored in the clear.

Authentication

Passwordless, with an optional second factor.

Wrenbase uses magic-link sign-in. No passwords stored, no password-reset surface to exploit. Turn on two-factor authentication and a 6-digit code from your authenticator app is required at sign-in too, so a stolen email link isn't enough to get in.

Screening

Bad actors stop before they reach you.

Inbound vendor submissions and public forms are screened before they reach you, combining sanctions checks, sender-reputation signals, and your own rules. Submissions that look fraudulent never land in your inbox.

Attachments

Files are validated before they're accepted.

Documents attached to an invoice or quote are checked before they're accepted. A file whose contents don't match its declared type is rejected outright, so nothing can pose as a different kind of file. Attachments are stored encrypted and only reach the people on that invoice.

AI usage

Your data is not training data.

When Wrenbase uses AI to draft invoices or follow-ups, your data is sent to AI providers only to generate the output. Our contracts forbid those providers from training their models on your data.

Regulatory posture

Where Wrenbase stands legally.

Wrenbase LLC is a US LLC operating from California. The compliance posture below applies to every Wrenbase account from day one.

  • Sanctioned-jurisdiction screening

    On inbound submissions and account signups.

  • GDPR and UK GDPR

    For EU and UK residents.

  • CCPA, CPRA, and US state privacy laws

    Defensible to the strictest US standard.

  • PCI DSS SAQ-A

    Via Stripe-hosted payment surfaces.

  • Privacy laws follow the user

    Wrenbase honors the privacy law of the jurisdiction where each user lives, not where Wrenbase is incorporated.

  • Strictest standard applies

    Where multiple regimes overlap, the most protective wins.

Audit log

On the record

Sent invoice INV-1042

Today 2:15 PM

You

Meridian Aerospace · $2,750

Drafted INV-1042

Today 2:14 PM

Revenue agent

Recurring schedule · monthly

Marked INV-1038 paid

Yesterday 4:32 PM

You

Check · $1,800

Sent reminder

Yesterday 11:08 AM

Wrenbase

INV-1037 · friendly nudge

Accepted QU-038

Mar 15

Customer

Meridian · $2,750

Audit trail

Every money-moving action, on the record.

Invoice drafts, sends, payments, reminders, and agent actions are timestamped and attributed to the actor (you, your team, or an agent acting on your behalf). When a customer disputes something three months later, the receipt is already there.

Common questions

The things security teams ask.

How does Wrenbase keep my data separate from other customers?
Every record in Wrenbase is scoped to your account. There is no path that returns another customer's information. When you and a vendor share an invoice, each side sees only their own view, never both at once.
Where are my payments processed?
Payments go through Stripe. Wrenbase never sees or stores card numbers or bank account details. We hold references to a payment, not the payment instrument itself.
Does Wrenbase staff have access to my data?
Wrenbase staff don't access your data in the normal course of running the product. If you need help and that help requires access, we'll ask you first.
How does sign-in work? Is there a password I need to manage?
No password. We email you a sign-in link. Tap it, you're in. Nothing to remember, nothing to reset, nothing to leak.
Can I add two-factor authentication?
Yes. Turn on an authenticator app from Settings, Security. After your usual email link, you enter a 6-digit code from an app like 1Password or Google Authenticator, so a stolen email link alone can't sign in as you. You also get one-time recovery codes in case you lose your phone.
Is my data encrypted?
Yes. Everything in transit is encrypted. Everything at rest is encrypted. The connections you make to other services like Google Drive or Calendar are encrypted too.
How are file attachments handled?
Every document you attach to an invoice or quote is checked before it's accepted. A file whose contents don't match its stated type is rejected, so a file can't pretend to be something it isn't. Attachments are stored encrypted and only ever reach the people on that invoice.
What gets recorded in the audit trail?
Every action that moves money or changes a record. Invoices sent, payments received, vendors approved, settings changed. Each event has who did it, what happened, and when. Exportable by request.
If our records lived in a spreadsheet, would we have any of this?
Not really. Spreadsheets don't track who edited what, don't keep history of past versions you can trust, and don't have access controls beyond who you share the file with. Once we're talking about money, that gap matters. Wrenbase keeps the record straight on its own.
Which privacy laws does Wrenbase follow?
Wrenbase honors the privacy law of the jurisdiction where each user lives, not where Wrenbase is incorporated. That includes GDPR in the EU and UK, CCPA in California, LGPD in Brazil, PIPEDA in Canada, and equivalents elsewhere.
Who is the legal entity behind Wrenbase?
Wrenbase LLC, a US LLC operating from California.