A hotel platform holds guest identity data, folios and payment references. Here is how we protect it.
Certificates are available for review under NDA during procurement. Where a market requires additional attestation, we will state clearly what we hold and what we do not.
TLS encryption for all client traffic. Database and backup encryption at rest. Card data is never stored on our platform — payments are tokenised through the licensed payment provider.
Role-based permissions inside the product, so a housekeeping account cannot read folios and a restaurant till cannot open rate management. Administrative access to client environments is granted by named individual and logged.
Automated daily backups with off-site replication. Cloud deployments run on a SQL cluster with load balancing. On-premise deployments support customer-controlled backup schedules.
Cloud or on-premise deployment. Where a market requires data to stay in-country or in-region, we scope that with you up front rather than discovering it at go-live.
Staged releases with a test environment. Client data is not used in non-production environments. Emergency changes follow a documented approval path.
Staff confidentiality undertakings, background checks on engineering roles, and access removed on exit. A named 7×24 escalation path for security incidents.
Security questions from procurement teams, and reports of suspected vulnerabilities, both come to the same place.
We acknowledge security reports within one business day. Please include steps to reproduce and do not test against live client environments.