Skip to main content

Protected by design

Your property records, held with care.

Sensitive financial, tenancy and property records deserve more than a vague promise. Tendmere combines protected connections, encrypted recovery, dedicated EU infrastructure and accountable privacy controls.

Start freeSee the safeguards

TLS + encrypted backups

Data protection

EU data centres

Data residency (UK-adequate)

UK GDPR controls

Privacy programme

FCA-authorised partner

Open Banking setup

Security measures

How we protect your data

Encryption in transit

All data transmitted between your device and our servers is encrypted using TLS 1.3, the latest transport security protocol.

Encrypted recovery

Database backups and recovery key material are encrypted with AES-256 before retention or off-server transfer.

Dedicated EU hosting

Core application, authentication, file, and database services run on dedicated EU-hosted infrastructure controlled by Tendmere. Carefully selected subprocessors are governed by documented data-protection safeguards.

UK GDPR controls

Tendmere is designed and operated to support UK GDPR and Data Protection Act 2018 obligations, including access, correction, portability, and deletion requests.

Accountable privacy programme

Privacy requests, processor records, access controls, incident handling, and retention decisions are managed under our documented data-protection programme.

FCA-authorised Open Banking partner

When Open Banking is enabled, it will use a provider authorised and regulated by the Financial Conduct Authority, with read-only access only. Live bank feeds remain gated by partner credentials.

No credential storage

We never see or store your bank login credentials. When Open Banking is enabled, the connection is handled entirely by our FCA-regulated partner — Tendmere only receives read-only transaction data.

Regular backups

Automated daily encrypted backups, off-server retention, and disposable restore drills protect recovery from hardware failures and incidents.

Access controls

Row-level security ensures you can only access your own data. Multi-factor authentication available for all accounts.

Audit logging

All significant actions are logged with timestamps for accountability and compliance audit trails.

Vulnerability monitoring

Continuous dependency scanning and security monitoring to identify and patch vulnerabilities before they become threats.

Data portability

Use the available CSV and PDF exports, or request a complete copy through our privacy data-request process. There are no exit fees.

Our promise

Data handling principles

Minimise collection

We only collect data necessary to provide the service. No tracking beyond essential analytics.

Never sell

Your data is never sold, rented, or shared with third parties for marketing. Period.

Protect every route

Connections use TLS; database backups and recovery key material are AES-256 encrypted before retention or off-server transfer.

Control data routes

Core services stay on dedicated EU infrastructure. We assess subprocessor locations and put the required UK data-protection safeguards in place.

Let you leave

Use available CSV exports or request a complete copy or account deletion through our privacy data-request process.

Be transparent

Our privacy policy is written in plain English. No legalese walls. No hidden clauses.

FAQ

Security questions

Found a vulnerability?

We welcome responsible disclosure. Email us and we’ll acknowledge your report promptly.

Your data is safe. Start managing.

Review Tendmere's current transport, storage, access-control and EU-hosting posture for the controlled web beta.

No credit card required · Controlled web beta for 1-2 properties