Trust
Security
Hospitality data includes payroll, guests, and vendors. We treat it that way.
Encryption everywhere
Data is encrypted in transit with TLS and at rest by our infrastructure provider.
Row-level isolation
Every table enforces database-level policies so one organization can never read another's records.
Role-based permissions
Twelve role levels from platform admin to shift lead, scoped by location and department.
Audit logging
Sensitive changes record old and new values with the actor and timestamp.
Least-privilege integrations
Connected providers use scoped credentials that you can revoke at any time.
Incident response
We investigate reports promptly and notify affected customers without undue delay.
Reporting a vulnerability
Email security@tomaitre.com with steps to reproduce. We acknowledge reports within two business days and will keep you updated through resolution. Please do not test against other customers' data.
Your responsibilities
- Use strong, unique passwords and remove access when staff leave.
- Grant the lowest role level that lets someone do their job.
- Review audit logs and integration connections periodically.
