Security

Built to keep each hotel's data where it belongs

StayFn handles reservation and guest data for many properties at once. Isolation, secrets and privacy are part of the design, not settings you have to remember.

Tenant isolation

  • PostgreSQL row-level security on every tenant table
  • Access without a tenant fails closed
  • The service runs as a role with data access only and no way to bypass row-level security; migrations use a separate role

Authentication and access

  • Tenant API keys are shown once and stored only as hashes
  • Keys carry scopes (invoke, read, webhook) and can expire or be revoked
  • Admins sign in with JWTs or your OIDC identity provider, with owner, operator and viewer roles

Secrets

  • Credentials are references to AWS Secrets Manager, HashiCorp Vault, Azure Key Vault or environment variables
  • Secret values are never stored in the database or returned by the API
  • Rotate OHIP credentials without a restart

Guest data

  • E-mail, phone and card patterns and guest-data fields are masked in every log line
  • The dashboard shows masked payloads
  • Retention windows per tenant delete old invocations, events, dead letters and audit records

Audit and observability

  • An audit trail of admin actions and function activity
  • Every OHIP call recorded against the invocation that made it
  • A correlation id on every log line, metric and trace

Platform hardening

  • Non-root container on a read-only file system
  • CSP, HSTS and strict headers, body size limits and load shedding
  • Vulnerability audits, CycloneDX SBOMs, pinned dependencies and a licence allow-list in CI
Data residency

Your data stays in the region you choose

StayFn Cloud runs in the EU or the US, and a tenant's data stays in its region. If your policies require it, run StayFn self-hosted in your own cloud account or data centre, where you control every byte.

Compare deployment options →

Working with your security team

We will walk your security and compliance team through the architecture, the data StayFn stores and how long it keeps it, and answer your questionnaire.

Contact us

Responsible use of Oracle's platform

StayFn follows OHIP's documented rules: one streaming consumer per chain and app key, a rate-limit budget per app key, and only operations from Oracle's published specifications. Credentials for your OHIP environment stay yours.

See StayFn run against OPERA Cloud

A 30-minute walkthrough: we connect to the OHIP sandbox, write a function together and watch it run in the dashboard.