Skip to content
SStaySynq

Security

Built on trust. Audited annually.

Hospitality runs on guest data. We treat it that way — with the controls, audits, and transparency hotels expect from a modern vendor.

SOC 2 Type IIISO 27001GDPRPCI-DSS

Controls

The full stack of security controls.

Encryption

TLS 1.3 in transit. AES-256 at rest. Database-level encryption with keys managed in HSM-backed KMS.

Access controls

Least-privilege RBAC. SSO/SAML available. Mandatory MFA for all staff. Quarterly access reviews.

Infrastructure

Hosted on hyperscaler cloud with multi-AZ failover. Network segmentation, WAF, DDoS protection, private networking.

Monitoring

Centralized SIEM, 24/7 alerting, anomaly detection, audit logging on every data access.

Incident response

Documented runbooks, on-call rotation, customer notification within 72 hours of confirmed breach.

Personnel

Background-checked staff, mandatory security training, signed confidentiality, scoped access.

Secure SDLC

Code review, dependency scanning, secret scanning, SAST/DAST, signed releases, immutable infrastructure.

Compliance

SOC 2 Type II, ISO 27001, GDPR-ready DPA, PCI-DSS via tokenization (no card data on our servers).

Certifications

Audited by independent firms.

Need the report? Request it from our team under NDA.

SOC 2 Type II

Annual audit by Big Four firm. Report available under NDA.

ISO 27001

Information Security Management System certified.

GDPR / UK GDPR

DPA, SCCs, and EU representative available.

PCI-DSS

Card data tokenized via processor. Never stored on our infrastructure.

Responsible disclosure

Found a vulnerability?

We welcome reports from security researchers. Email security@staysynq.com with reproduction steps. We acknowledge within 24 hours and aim to resolve critical issues within 7 days. We do not pursue legal action against researchers who follow our policy.