Data Protection Brief

Your guest data, under lock and key.

How Serai protects your leads and guest information — the same five commitments, in plain English, that we hold ourselves to every day.

01

Only your people see your data

You decide who joins your hotel. Inside it, each team member sees only the leads they created or were assigned — one salesperson can't browse another's prospects. Managers see the full pipeline; only you, as owner, see everything. And no staff member can export or download the entire lead list.

HowRole-based access control checks every request against the user's rank and department before a single record is returned — enforced on the server, not the screen.
02

One hotel can never see another's data

Every hotel on Serai is sealed off from every other one. Your data lives behind a wall enforced inside the database — so even a programming mistake physically cannot hand your leads to a neighbouring hotel. This isolation is verified by automated tests on every release.

HowPostgreSQL Row-Level Security. Every record carries your hotel's ID and is filtered by the database engine on every query — multi-tenancy is a property of the database, not the code.
03

Locked down against outside attackers

Your data travels fully encrypted and sits behind Cloudflare — the same protection network trusted by major banks and airlines. It absorbs denial-of-service attacks, blocks malicious bots and known attack patterns before they ever reach the server, and hides the server's real address. Passwords are stored with one-way encryption that not even we can reverse.

HowTLS encryption in transit · Cloudflare WAF, DDoS & bot mitigation at the edge · Argon2id password hashing · short-lived sessions with rotating refresh tokens.
04

Even we can't wander in

The platform's administrator has no standing access to your hotel's data. To help with a specific support issue, access must be requested and can only be approved by you — it is strictly time-limited, and your leads' contact details stay masked unless you personally grant it. When the window closes, access is gone.

HowTime-boxed, hotel-admin-approved support grants; contact details masked by default even during a session; the grant can be ended by you at any moment.
05

Every action is watched — including ours

Founders and developers are held to the same standard as anyone else. Every action against the database is written to a permanent audit trail, and a copy is streamed the instant it happens to an outside channel we can't edit — so no record can be quietly altered or deleted after the fact. Your data is also backed up automatically, off-site, every night.

HowImmutable in-database audit log + real-time mirror to an out-of-band channel (tamper-evident) · nightly encrypted off-site backups with monitored success checks.
The people accountable for your data

Two decades each, securing sensitive data

Serai is built by founders with 20+ years each in enterprise software — much of it spent handling financial and personal records under strict security regimes. Protecting sensitive data isn't new terrain for us; it's the work we've done our whole careers.

Incentives that align with yours

We're an established, independently-funded team with no need — and no intention — to monetise anyone's data. Serai earns from one thing: hotels paying for software that runs their operations. Integrity, transparency and ethics are the ground the company stands on, and your data staying yours is simply how we work.

Built to enterprise standards. Explained in plain English.

We're glad to walk you or your IT advisor through any of this in as much technical depth as you'd like.

Talk to us →