Security
Security as practice, not a certificate
We can point at the controls running in the platform today, and we can tell you plainly what we have not done. Nothing on this page is a certification claim.
Running today
Your agency’s data is separated from every other agency’s
- Isolation is enforced in three places: the route, the controller, and the database row.
- A request for a record that is not yours is answered as “not found”, not as “forbidden”, so nothing leaks through what the error says.
- Seeing a passenger’s full identity data needs its own separate permission, held by very few people.
Passenger data at rest
- Passport numbers, dates of birth and passenger emails are encrypted at rest with AES-256.
- The keys live in a rotating key ring, with a separately derived key for each purpose, so one key never unlocks everything.
- Search still works on those encrypted fields through blind indexes, so records are found without being decrypted.
- Card, key and token shapes are stripped from our logs, and identity data is masked before any call leaves the platform.
- A retention command purges data we no longer need to hold.
Getting in, and staying in
- Two-factor sign-in by email: required for our own staff and administrators, and available on every agency account.
- The agent portal and the admin portal run on separate hostnames with separate session cookies, and administrators cannot use “remember me”.
- Sessions expire on idle and on an absolute limit, are bound to the browser they started in, are capped per account, and can be revoked from our side.
- Four tiers of rate limiting, with the tightest caps on issuing, voiding and refunding. An account locks after seven failed sign-in attempts.
- About 212 named permissions across five groups. A staff sub-account you create starts with none of them.
- The browser session itself is protected by a strict Content Security Policy in enforcement mode, a per-tab CSRF token with origin validation, and HSTS.
What can be shown afterwards
- Every sign-in attempt is logged.
- Every change to who can do what is written to an audit table, with a correlation ID that ties it back to the exact request.
- One command runs our security gate before a release: an access-control scanner, a validation-boundary check, a legacy password-hash burn-down and a cryptography self-test.
- The money events we exchange with our accounting platform are signed, replay-protected and idempotent, so the same event can never post twice.
- Most of these controls are annotated in our own source code with the named security control they implement.
Not claimed
What we do not claim
- We have not been independently penetration tested, and we hold no SOC 2 or ISO certification. If you need one, ask us and we will tell you where we are.
- We publish no uptime, service-level, disaster-recovery or data-residency figures, because we have none documented.
- We do not accept card payments and we make no PCI claim. Account top-ups are a bank or exchange transfer against a named recipient, with proof of transfer.
- Two-factor sign-in is available on every agency account, but we do not force it on you. We do force it on ourselves.
- We do not claim device-bound sessions or forced password rotation, and we do not email you when a new device signs in.
- The documents you send us when you apply are uploaded over an encrypted connection and held inside the booking platform, never on this website. We do not claim more than that.
Create your agency account
Register on the platform, we review and agree terms with you directly, then we activate your account.
Have these ready to speed things up:
- Commercial register or trade licence
- Owner or authorised-signatory ID
- Agency address, phone and email