Skip to documentation content

Documentation Category

Security & Privacy

Protect booking data, credentials, licenses, update packages and external calendar sources throughout operation.

Articles

Protect booking data and define retention Map booking snapshots, guest data, payment records and external blocks to a documented retention and access policy. Apply roles, capabilities and least privilege Limit booking, channel, license and update actions to the smallest trusted staff group and retain a reviewable audit trail. Protect payment secrets and webhooks Store gateway credentials safely and verify every callback before payment ledger or booking state can change. Secure licenses and update packages Operate Pro entitlement and Aurelia updates with least exposure, trusted transport, strict package identity and safe failure. Secure iCal sources and export links Protect imported feed URLs and per-room export tokens while preserving safe occupancy behavior when a source fails. Back up, restore and respond to incidents Use a tested recovery plan that protects immutable booking evidence, occupancy blocks, credentials and public access tokens during an incident. Report a security issue responsibly Send a private, reproducible and redacted vulnerability report without exposing guests, credentials, tokens or exploitable details publicly.