Skip to content
Security

What the software actually does

We don't quote certifications we don't hold. Instead, here is what the software does to keep each property's data separate, controlled and recoverable.

Each property sees only its own data

Tenant isolation is enforced in every database query and backed by database constraints, so one property's records can't show up in another's.

Role-based access

Eight built-in roles and fine-grained permissions decide who can see and do what.

Full audit trail

Who changed what, and when, is recorded.

Passwords hashed with Argon2id

Passwords are never stored as text — only as Argon2id hashes.

Sign-in protection

Repeated failed sign-ins are throttled, and the session is renewed on every sign-in.

No third-party scripts

A strict Content Security Policy allows only our own files. Every script, style and icon is served from our own server — no CDNs, no trackers.

HTTPS

Traffic between the browser and the server is encrypted.

Verified backups

Backups are verified by checksum, and a safety copy is taken before any restore.

Signed licences

Licences are signed with Ed25519, so a licence can't be forged or edited.

Operator access is logged

When our operators need to enter a property, it's an explicit step, and it is logged.

Self-hosted stays with you

On the self-hosted edition, your data never leaves your server.

Ownership

Your data, your copy

You are never locked out of your own records.

  • Export any report to CSV, for any date range
  • On the self-hosted edition, take a full backup whenever you like, and keep an off-site copy over FTPS or on S3-compatible storage

Have a security question?

Ask us anything about how your data is handled — we'd rather answer it before you sign up than after.