Building hospitality technology since 1993 · Shenzhen, China
Home / Security

Security & compliance

A hotel platform holds guest identity data, folios and payment references. Here is how we protect it.

Certifications

Independently audited

MLPS Level 3China Multi-Level Protection Scheme · filed for the GEMSTAR tourism information system
ISO 9001:2015Quality management system certified 2025
National High-Tech EnterpriseCertified by the Shenzhen science & technology authority
84 software copyrightsFully self-developed IP, no white-labelling

Certificates are available for review under NDA during procurement. Where a market requires additional attestation, we will state clearly what we hold and what we do not.

Controls

What we actually do

Data in transit and at rest

TLS encryption for all client traffic. Database and backup encryption at rest. Card data is never stored on our platform — payments are tokenised through the licensed payment provider.

Access control

Role-based permissions inside the product, so a housekeeping account cannot read folios and a restaurant till cannot open rate management. Administrative access to client environments is granted by named individual and logged.

Backup and resilience

Automated daily backups with off-site replication. Cloud deployments run on a SQL cluster with load balancing. On-premise deployments support customer-controlled backup schedules.

Data residency

Cloud or on-premise deployment. Where a market requires data to stay in-country or in-region, we scope that with you up front rather than discovering it at go-live.

Change and release control

Staged releases with a test environment. Client data is not used in non-production environments. Emergency changes follow a documented approval path.

People and process

Staff confidentiality undertakings, background checks on engineering roles, and access removed on exit. A named 7×24 escalation path for security incidents.

Reporting

Found something, or need a security review?

Security questions from procurement teams, and reports of suspected vulnerabilities, both come to the same place.

Contact the security team

We acknowledge security reports within one business day. Please include steps to reproduce and do not test against live client environments.