Skip to main content

Security and your data

Signing in​

You sign in with your work email and a one-time code sent to it. There is no password. You can only join by invitation. Sessions end after 8 hours without use.

Who can see what​

Each company's data is kept separate from every other company's. Within your company, what each person can see and do depends on their role and depots. See roles and permissions.

Sensitive changes, such as a new MCS login, need a second admin.

MCS support​

MCS support staff can open a time-limited support session to help you, for a stated reason. Anything they change appears in your activity log under their own name, marked MCS.

Emails from senders​

  • Rent Stream AI checks that each email really came from the sender's own email system. If it did not, the sender is treated as unknown, a person always deals with the work, and Rent Stream AI never writes to them automatically.
  • Emails are always shown as plain text, never with the sender's formatting.
  • Out-of-office replies and other automatic emails are ignored.
  • Rent Stream AI only ever emails the original sender, never people copied in.

Your MCS data​

MCS stays the system of record. Rent Stream AI reads from MCS only through read-only endpoints you install, and creates records only through MCS's own XML gateway. A record picked from what a sender wrote is never used without being found in MCS or confirmed by a person.

AI​

Rent Stream AI uses Anthropic's Claude models, through the Anthropic API, to sort, read and understand emails and documents. Anthropic does not use data sent through its API to train its models.

How long data is kept​

MCS remains the system of record for everything created there.

:::note Coming later Automatic removal of emails, documents and work item detail after your company's retention period (13 months by default, or as short as 90 days) is being built. :::