Information Security Policy
How we protect the systems and data our customers depend on, under our ISO/IEC 27001 certified information security management system.
Awaiting legal review. The structure below is agreed. The clauses under each heading are to be drafted and approved by counsel before this page is published.
Purpose and scope
The systems, data and people covered, and the relationship to our ISO/IEC 27001 certification.
Governance and responsibility
Who owns information security, how it is reviewed, and the reporting line to management.
Risk assessment
How security risks are identified, rated and treated, and how often that is repeated.
Access control
Least-privilege principles, joiner-mover-leaver process, and administrative access to customer environments.
Data classification and handling
How hotel operating data and guest personal data are classified, stored and transmitted.
Encryption and key management
Requirements in transit and at rest, and how keys are held.
Hosting and physical security
Controls at the hosting layer, including isolation between customers and data residency commitments.
Change and vulnerability management
Patching cadence, testing before release, and how vulnerabilities are tracked to closure.
Supplier and third-party security
Assessment of subprocessors and vendors, and the terms required of them.
Incident response
Detection, triage, containment, customer notification timelines and post-incident review.
Business continuity and recovery
Backup, tested restore, and the recovery objectives we commit to.
Awareness and training
Security training for staff, and the additional requirements for engineering and support roles.
Compliance and audit
Internal audit, external certification audits, and how findings are closed out.
Reporting a security concern
Suspected vulnerabilities or incidents should be reported to [email protected] without delay. Customers with a live incident should also call the 24/7 support line.