Trust at Wrenbase
Built to be trusted with your money.
Wrenbase is built for businesses that handle money seriously, with each business's data kept separate, encrypted infrastructure, passwordless sign-in, screening on the bills that come in, and payments handled by Stripe. These are commitments we hold ourselves to, not a checklist.
The promise
Wrenbase is built on commitments that ship the day you sign up. Every claim below is enforced in the product itself, on every request, rather than living only in a compliance document.
Tenant isolation
Your data never touches another tenant's.
Each business's data is isolated at the deepest layer, so one business's records are physically walled off from another's. An employee working in one account cannot reach another account's data through any path.
- Every database query carries your account as a filter. There is no path that returns another customer's rows.
- Shared records (an invoice between you and a vendor) show each side only their own view, never both at once.
- Wrenbase staff don't access your data in the normal course of running the product. If you request support that requires it, we'll ask first.
Tenant A
Invoice INV-1042
Customer: Meridian Aerospace
Payment $2,750
Tenant B
Invoice INV-2057
Customer: Müller GmbH
Payment €3,200
Isolation enforced at the deepest layer
Commitments
Commitments that run on every request.
Sanctions screening
Sanctioned jurisdictions blocked at the door.
Wrenbase screens Invoice Me submissions and account signups for sanctions compliance. Anything tied to a comprehensively sanctioned jurisdiction is stopped before it reaches your inbox, so you stay on the right side of the rules.
Payments
Stripe-hosted. Never on our servers.
Wrenbase never touches your or your customers' card numbers or bank account details. All payments flow through Stripe-hosted surfaces. Wrenbase stores references and metadata, not payment instruments.
Encryption
In transit and at rest, end to end.
All connections use TLS. All data at rest is encrypted on AWS-managed infrastructure. The access tokens for services you connect are encrypted separately, so they're never stored in the clear.
Authentication
Passwordless, with an optional second factor.
Wrenbase uses magic-link sign-in. No passwords stored, no password-reset surface to exploit. Turn on two-factor authentication and a 6-digit code from your authenticator app is required at sign-in too, so a stolen email link isn't enough to get in.
Screening
Bad actors stop before they reach you.
Inbound vendor submissions and public forms are screened before they reach you, combining sanctions checks, sender-reputation signals, and your own rules. Submissions that look fraudulent never land in your inbox.
Attachments
Files are validated before they're accepted.
Documents attached to an invoice or quote are checked before they're accepted. A file whose contents don't match its declared type is rejected outright, so nothing can pose as a different kind of file. Attachments are stored encrypted and only reach the people on that invoice.
AI usage
Your data is not training data.
When Wrenbase uses AI to draft invoices or follow-ups, your data is sent to AI providers only to generate the output. Our contracts forbid those providers from training their models on your data.
Regulatory posture
Where Wrenbase stands legally.
Wrenbase LLC is a US LLC operating from California. The compliance posture below applies to every Wrenbase account from day one.
Sanctioned-jurisdiction screening
On inbound submissions and account signups.
GDPR and UK GDPR
For EU and UK residents.
CCPA, CPRA, and US state privacy laws
Defensible to the strictest US standard.
PCI DSS SAQ-A
Via Stripe-hosted payment surfaces.
Privacy laws follow the user
Wrenbase honors the privacy law of the jurisdiction where each user lives, not where Wrenbase is incorporated.
Strictest standard applies
Where multiple regimes overlap, the most protective wins.
Audit log
On the recordSent invoice INV-1042
Today 2:15 PM
Meridian Aerospace · $2,750
Drafted INV-1042
Today 2:14 PM
Recurring schedule · monthly
Marked INV-1038 paid
Yesterday 4:32 PM
Check · $1,800
Sent reminder
Yesterday 11:08 AM
INV-1037 · friendly nudge
Accepted QU-038
Mar 15
Meridian · $2,750
Audit trail
Every money-moving action, on the record.
Invoice drafts, sends, payments, reminders, and agent actions are timestamped and attributed to the actor (you, your team, or an agent acting on your behalf). When a customer disputes something three months later, the receipt is already there.
Common questions
The things security teams ask.
- How does Wrenbase keep my data separate from other customers?
- Every record in Wrenbase is scoped to your account. There is no path that returns another customer's information. When you and a vendor share an invoice, each side sees only their own view, never both at once.
- Where are my payments processed?
- Payments go through Stripe. Wrenbase never sees or stores card numbers or bank account details. We hold references to a payment, not the payment instrument itself.
- Does Wrenbase staff have access to my data?
- Wrenbase staff don't access your data in the normal course of running the product. If you need help and that help requires access, we'll ask you first.
- How does sign-in work? Is there a password I need to manage?
- No password. We email you a sign-in link. Tap it, you're in. Nothing to remember, nothing to reset, nothing to leak.
- Can I add two-factor authentication?
- Yes. Turn on an authenticator app from Settings, Security. After your usual email link, you enter a 6-digit code from an app like 1Password or Google Authenticator, so a stolen email link alone can't sign in as you. You also get one-time recovery codes in case you lose your phone.
- Is my data encrypted?
- Yes. Everything in transit is encrypted. Everything at rest is encrypted. The connections you make to other services like Google Drive or Calendar are encrypted too.
- How are file attachments handled?
- Every document you attach to an invoice or quote is checked before it's accepted. A file whose contents don't match its stated type is rejected, so a file can't pretend to be something it isn't. Attachments are stored encrypted and only ever reach the people on that invoice.
- What gets recorded in the audit trail?
- Every action that moves money or changes a record. Invoices sent, payments received, vendors approved, settings changed. Each event has who did it, what happened, and when. Exportable by request.
- If our records lived in a spreadsheet, would we have any of this?
- Not really. Spreadsheets don't track who edited what, don't keep history of past versions you can trust, and don't have access controls beyond who you share the file with. Once we're talking about money, that gap matters. Wrenbase keeps the record straight on its own.
- Which privacy laws does Wrenbase follow?
- Wrenbase honors the privacy law of the jurisdiction where each user lives, not where Wrenbase is incorporated. That includes GDPR in the EU and UK, CCPA in California, LGPD in Brazil, PIPEDA in Canada, and equivalents elsewhere.
- Who is the legal entity behind Wrenbase?
- Wrenbase LLC, a US LLC operating from California.
Documents and references
Full transparency. Every document linked.
Security disclosures, compliance questions, DPA requests
A human at Wrenbase answers.
