Trust

Security

Hospitality data includes payroll, guests, and vendors. We treat it that way.

Encryption everywhere

Data is encrypted in transit with TLS and at rest by our infrastructure provider.

Row-level isolation

Every table enforces database-level policies so one organization can never read another's records.

Role-based permissions

Twelve role levels from platform admin to shift lead, scoped by location and department.

Audit logging

Sensitive changes record old and new values with the actor and timestamp.

Least-privilege integrations

Connected providers use scoped credentials that you can revoke at any time.

Incident response

We investigate reports promptly and notify affected customers without undue delay.

Reporting a vulnerability

Email security@tomaitre.com with steps to reproduce. We acknowledge reports within two business days and will keep you updated through resolution. Please do not test against other customers' data.

Your responsibilities

  • Use strong, unique passwords and remove access when staff leave.
  • Grant the lowest role level that lets someone do their job.
  • Review audit logs and integration connections periodically.