Skip to content
RoomAnchorPMS
Security

Your guests trust you. You can trust us.

How RoomAnchor protects your property, your team and your guests. Only what the system really does today, in plain words.

Data protection

Eight things that keep your data safe.

A hotel holds names, phone numbers, ID documents and money. These are the protections built into every plan.

  1. 01

    Secrets are encrypted

    Payment gateway keys, SMS credentials and other secret settings are encrypted before they are stored.

    Guest identification numbers are encrypted too, and only shown masked to staff who check guests in or edit guest profiles.

  2. 02

    Every connection over HTTPS

    Every page and API call is served over HTTPS, with security headers on every response. Sessions are encrypted and their cookies are only sent over secure connections.

  3. 03

    Your organisation, kept separate

    Every record belongs to one organisation, and every query is limited to the organisation you are signed in to. One hotel can never see another hotel’s guests, bookings or money.

    Inside your organisation, staff can be limited to the properties they work at.

  4. 04

    Roles and permissions

    Twenty ready-made roles, from front desk agent to night auditor and accountant, each limited to the screens and actions that job needs. Copy one and adjust it, or build your own.

  5. 05

    Two-factor sign in

    Anyone can add a code from an authenticator app to their sign in, with recovery codes for a lost phone. Your organisation can make it required for everyone.

    Repeated failed sign ins are slowed down, and sensitive actions ask for the password again.

  6. 06

    An audit log of every change

    The audit log records who changed what, when and from where, so you can answer questions about a booking, a refund or a rate without guessing.

  7. 07

    Daily backups, kept off-site

    The database is backed up every day into an encrypted archive, with copies kept off-site and alerts if a backup is missing.

  8. 08

    Test mode for payments

    While you set up and train, test mode lets every payment succeed without a gateway. Staff and guests are told clearly that no money is taken.

Shared responsibility

What we do, and what you control.

What we do

  • Encrypt gateway keys, SMS credentials and guest ID numbers
  • Serve everything over HTTPS with encrypted sessions
  • Keep each organisation’s data separate on every request
  • Back up the database daily, encrypted, with off-site copies
  • Hash API keys and sign every webhook
  • Show test mode clearly so no one mistakes it for real payments

What you control

  • Who is on your team and which role each person has
  • Which properties each person can open
  • Whether two-factor sign in is required
  • Signed in sessions, which you can see and sign out
  • Whether check-in records guest identification
  • API keys, with scopes, IP limits and expiry dates
Questions

Security, answered.

Is our data backed up?

Yes. The database is backed up on a schedule, backups are monitored and old ones are cleaned up automatically.

Does RoomAnchor support two-factor authentication?

Yes. Anyone can turn on two-factor authentication with an authenticator app and recovery codes, and owners can require it for every staff member before they can use the workspace.

Can I control what each staff member can see and do?

Yes. Every organisation starts with ready-made roles such as front desk agent, accountant and room attendant. You can edit them or create your own in the permission matrix, and limit each person to the properties they work at.

Can I see who changed what?

Yes. The audit log records changes and key actions with who made them, when, and the IP address they came from.

How are guest ID numbers and payment credentials protected?

Guest identification numbers are encrypted and only shown masked to staff who need them. Payment gateway and SMS credentials are encrypted and never shown again after they are saved.

Found a problem, or have a question?

Write to us about anything security related, including a weakness you think you have found. A person reads every message.

support@example.com

See it working with your own rooms.

A 30 minute call with someone who has run a front desk. Bring your questions and your room list.