Security

What we actually do to keep your data safe — described plainly, and without claiming certifications we do not hold.

Encryption

Data is encrypted in transit with TLS. At rest, data is stored on infrastructure that provides encryption at rest. Connected-mailbox credentials are additionally encrypted at the application level, so they are not readable from the database contents alone.

Tenant isolation

One hotel cannot reach another’s data. Access is enforced at the database level with row-level security: every customer table restricts reads to members of the owning workspace and writes to authorised roles. This is applied per table, not by hiding links in the interface.

Authentication

Sign-in is handled by our authentication provider. Passwords are stored only as hashes; we never see the password itself. Sign-in with Google is available.

Secrets

Service credentials and customer secrets are held server-side only and are never included in the browser bundle. Mailbox credentials and payment references are readable only by the server.

Abuse and rate limiting

Endpoints that cost money or could be abused are rate limited, keyed on the address our platform verifies rather than a header a caller can set, with a global daily ceiling as a backstop. Every send checks a suppression list, and outreach carries a working opt-out.

Infrastructure

We build on established infrastructure providers (for hosting, database and authentication) that maintain their own recognised security certifications and backups. Those certifications are the providers’, not ours. We do not ourselves hold ISO 27001, SOC 2, or a published penetration test, and we will name a certificate rather than imply one if that changes.

Access controls

Access to production data is limited to those who need it to operate the service, and administrative actions are recorded to an audit log that the administrator cannot themselves read or alter.

Responsible disclosure

If you believe you have found a security issue, please tell us before disclosing it publicly. Email security@roomradius.io with enough detail to reproduce it. We will acknowledge your report, work to fix confirmed issues promptly, and we will not pursue researchers who act in good faith, avoid privacy violations and data destruction, and give us reasonable time to respond.

Incident response

We handle personal-data breaches in accordance with applicable data-protection law, including notifying customers, supervisory authorities and affected individuals where legally required.