Your guests trust you. You can trust us.
How RoomAnchor protects your property, your team and your guests. Only what the system really does today, in plain words.
Data protection
Eight things that keep your data safe.
A hotel holds names, phone numbers, ID documents and money. These are the protections built into every plan.
01
Secrets are encrypted
Payment gateway keys, SMS credentials and other secret settings are encrypted before they are stored.
Guest identification numbers are encrypted too, and only shown masked to staff who check guests in or edit guest profiles.
02
Every connection over HTTPS
Every page and API call is served over HTTPS, with security headers on every response. Sessions are encrypted and their cookies are only sent over secure connections.
03
Your organisation, kept separate
Every record belongs to one organisation, and every query is limited to the organisation you are signed in to. One hotel can never see another hotel’s guests, bookings or money.
Inside your organisation, staff can be limited to the properties they work at.
04
Roles and permissions
Twenty ready-made roles, from front desk agent to night auditor and accountant, each limited to the screens and actions that job needs. Copy one and adjust it, or build your own.
05
Two-factor sign in
Anyone can add a code from an authenticator app to their sign in, with recovery codes for a lost phone. Your organisation can make it required for everyone.
Repeated failed sign ins are slowed down, and sensitive actions ask for the password again.
06
An audit log of every change
The audit log records who changed what, when and from where, so you can answer questions about a booking, a refund or a rate without guessing.
07
Daily backups, kept off-site
The database is backed up every day into an encrypted archive, with copies kept off-site and alerts if a backup is missing.
08
Test mode for payments
While you set up and train, test mode lets every payment succeed without a gateway. Staff and guests are told clearly that no money is taken.
What we do, and what you control.
What we do
- Encrypt gateway keys, SMS credentials and guest ID numbers
- Serve everything over HTTPS with encrypted sessions
- Keep each organisation’s data separate on every request
- Back up the database daily, encrypted, with off-site copies
- Hash API keys and sign every webhook
- Show test mode clearly so no one mistakes it for real payments
What you control
- Who is on your team and which role each person has
- Which properties each person can open
- Whether two-factor sign in is required
- Signed in sessions, which you can see and sign out
- Whether check-in records guest identification
- API keys, with scopes, IP limits and expiry dates
Security, answered.
Is our data backed up?
Yes. The database is backed up on a schedule, backups are monitored and old ones are cleaned up automatically.
Does RoomAnchor support two-factor authentication?
Yes. Anyone can turn on two-factor authentication with an authenticator app and recovery codes, and owners can require it for every staff member before they can use the workspace.
Can I control what each staff member can see and do?
Yes. Every organisation starts with ready-made roles such as front desk agent, accountant and room attendant. You can edit them or create your own in the permission matrix, and limit each person to the properties they work at.
Can I see who changed what?
Yes. The audit log records changes and key actions with who made them, when, and the IP address they came from.
How are guest ID numbers and payment credentials protected?
Guest identification numbers are encrypted and only shown masked to staff who need them. Payment gateway and SMS credentials are encrypted and never shown again after they are saved.
Found a problem, or have a question?
Write to us about anything security related, including a weakness you think you have found. A person reads every message.
See it working with your own rooms.
A 30 minute call with someone who has run a front desk. Bring your questions and your room list.