Security
Asyncotel holds your guests’ details and your property’s finances. You are entitled to a straight account of how that is handled — including the parts we are still working on.
Controls
We use the same three states here that we use across the rest of the site. A control marked planned is one we have designed and not implemented.
Payments run through Razorpay, which is PCI-DSS certified. Asyncotel stores the payment and order references and masked details — never full card numbers or CVVs.
All traffic between your browser and Asyncotel runs over TLS. Integration calls to third parties are made over HTTPS.
Staff are assigned department roles, and permissions are resolved per member against the plan your property is on. Housekeeping does not see payroll; outlet staff do not see the ledger.
Sessions are server-side and signed. Signing out, changing workspace or removing a member takes effect on the server, not just in the browser.
API keys and credentials are supplied to the running service as environment configuration. No credential is committed to source control.
Each property is a separate workspace. Records, cached data and file storage are keyed to the property they belong to.
Significant actions are recorded. A complete, reviewable audit trail spanning every module is still being extended.
Database and object storage encryption is being formalised. We are not claiming application-level encryption at rest today.
Error tracking, uptime monitoring and on-call alerting are not yet in place. This is our next infrastructure priority and we would rather say so than imply otherwise.
Asyncotel has not been through a third-party penetration test, and holds no SOC 2 or ISO 27001 certification. If your procurement process requires either, talk to us before you buy.
Scoping access for external operators — a revenue manager who sees rates but not salaries — is designed and not yet built.
Reporting
If you believe you have found a vulnerability in Asyncotel, tell us before you tell anyone else and we will work with you on it.
Email admin@asyncotel.com with enough detail to reproduce the issue. We will acknowledge it and keep you updated while we work on a fix.
We do not currently run a paid bug bounty programme. We will credit you if you would like to be credited.