Skip to content

Security

Security designed around property boundaries.

We describe only safeguards implemented and verified in GuestCurrent. We do not claim certifications that have not been completed.

Verified safeguards, stated plainly and without invented certification claims.

Tenant isolation

Operational records are scoped to an organisation and property.

Property-level access

Staff explicitly switch only among properties assigned to them.

Secure guest links

Links expire, can be revoked and permit only named reservation actions.

Role-based permissions

Property roles and organisation administration remain separate.

Audit trails

Elevated and guest self-service changes create traceable records.

Payment architecture

Credentials remain server-side; provider events are verified and idempotent.

Data separation

Internal notes and unrelated property records stay outside guest responses.

Security testing

Isolation and permission scenarios are covered by repeatable tests.

Compliance roadmap

Future reviews will be stated only when complete.

Formal certifications, production provider reviews, retention commitments and commercial incident terms remain future work. No certification is implied today.

Review data processing