Security
Security and data practices.
Last updated: 2026-08-03
This page covers security and data practices for Solenter and its portfolio of products: Hostodian, TargetMock, and BlueLocale. Where practices differ between products, those differences are noted below. Product-specific documentation is also published on each product's own site.
Hosting and Infrastructure
All Solenter products are hosted within the United States on infrastructure managed by Solenter directly. Hostodian, which provides the underlying infrastructure, is itself operated by Solenter.
Customer data is not transferred to infrastructure located outside the United States without explicit notice and, where required by law, explicit consent.
Encryption
All data is encrypted in transit using TLS 1.2 or higher. Data at rest is encrypted using AES-256. Encryption keys are managed by Solenter and rotated on a defined schedule.
Data Retention and Deletion
Customer data is retained for the duration of the customer relationship. Upon account closure, customer data is deleted within 30 days, except where retention is required by law.
Customers may request deletion of their data at any time by contacting hello@solenter.com. Requests are processed within 14 days.
Subprocessors
Solenter uses a limited number of subprocessors. Changes to the subprocessor list are communicated to customers with 30 days' notice.
Complete subprocessor list to be published at launch. This table is updated when subprocessors are added or removed.
Access Control
Access to production systems is restricted to Solenter staff with a demonstrated operational need. All access is logged. Privileged access requires multi-factor authentication.
Staff do not access customer data unless required to resolve a support issue and, where required, only with documented authorization.
Incident Response
In the event of a confirmed security incident affecting customer data, affected customers will be notified within 72 hours of Solenter becoming aware of the incident. Notification will include the nature of the incident, the data affected, and the steps taken or being taken in response.
Reporting a Vulnerability
If you believe you have found a security vulnerability in any Solenter product or infrastructure, please report it to hello@solenter.com.
We ask that you give us a reasonable amount of time to investigate and address the issue before making it public. We will acknowledge receipt within 2 business days and provide an initial assessment within 7 business days.
A machine-readable disclosure policy is available at /.well-known/security.txt.
Product-Specific Notes
As the infrastructure layer for Solenter products, Hostodian operates the physical and virtual resources. Security practices for the underlying infrastructure are covered above.
TargetMock handles assessment data, including learner responses and performance records. This data is treated as sensitive and is not shared with third parties for advertising or analytics purposes. FERPA-relevant considerations apply to institutional customers.
BlueLocale provides independent property market analysis and does not process third-party personal data as part of its core service. Account and usage data is retained only to operate the platform and is never sold or shared with brokers, developers, or advertisers.