
Security & Compliance
Last Updated: April 18, 2026
Our Commitment to Security
At RevStay, security is foundational to everything we build. We handle sensitive guest data, payment information, and property management credentials—and we take that responsibility seriously. This page outlines our security practices and commitments to you.
Encryption at Rest
- All sensitive credentials (PMS API keys, OAuth tokens) are encrypted using AES-256-GCM
- Database hosted on infrastructure with automatic encryption at rest
- Encryption keys are managed separately from application data
Encryption in Transit
- All connections use TLS 1.2 or higher (TLS 1.3 preferred)
- HTTPS enforced on all endpoints
- HSTS headers prevent downgrade attacks
Authentication & Access Control
- Authentication powered by Clerk, a SOC 2 Type II certified identity provider
- Multi-factor authentication (MFA) available for all accounts
- Session tokens validated on every request
- Role-based access control for admin functions
- Automatic session expiration and secure logout
Payment Security
RevStay never stores credit card numbers or sensitive payment data directly. All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor.
- No card data touches our servers
- Stripe handles all PCI compliance requirements
- Webhook signatures verified cryptographically
- Idempotency controls prevent duplicate charges
Infrastructure Security
Hosting
- Application hosted on Vercel (SOC 2 Type II certified)
- Database hosted on Neon (PostgreSQL with automatic encryption)
- Geographic data residency in United States
- Automatic backups with point-in-time recovery
Network Security
- DDoS protection via edge network
- Web Application Firewall (WAF) rules
- Rate limiting on API endpoints
- SSL/TLS termination at edge
Third-Party Integrations
We carefully vet all third-party services and only partner with providers that meet our security standards. All of our critical infrastructure providers are SOC 2 Type II certified, including:
- Stripe (Payment Processing) – PCI DSS Level 1, SOC 2
- Clerk (Authentication) – SOC 2 Type II
- Twilio (SMS Delivery) – SOC 2, ISO 27001
- Resend (Email Delivery) – SOC 2 Type II
- Vercel (Application Hosting) – SOC 2 Type II
- Neon (Database) – SOC 2 Type II
API Security
- All API inputs validated using strict schemas
- Rate limiting prevents abuse and brute force attacks
- Webhook signatures verified on all incoming webhooks
- CORS policies restrict cross-origin requests
- SQL injection prevention via parameterized queries
Data Privacy & GDPR
- Data minimization: We only collect what's necessary
- Right to access: Users can request their data
- Right to deletion: Accounts can be fully deleted
- Data portability: Export your data anytime
- Clear consent mechanisms for SMS marketing
For detailed information, see our Privacy Policy.
SMS Compliance (TCPA)
- Explicit opt-in required before sending marketing messages
- Easy opt-out via STOP keyword
- Consent records maintained indefinitely
- Message frequency controls
- Clear identification of message sender
For detailed information, see our SMS Consent Policy.
Monitoring & Incident Response
- 24/7 application monitoring
- Automated alerting for anomalies and errors
- Audit logging for sensitive operations
- Incident response procedures documented
- Regular security reviews of access logs
Business Continuity
- Regular database backups
- Point-in-time recovery available
- Multi-region failover capabilities
- High availability infrastructure
Security Questionnaires
We understand enterprise customers often require security assessments. We're happy to complete your security questionnaire or provide additional documentation. Contact us at admin@rev-stay.com with your requirements.
Responsible Disclosure
If you discover a security vulnerability, please report it responsibly to admin@rev-stay.com. We appreciate security researchers who help us keep our platform safe and will acknowledge valid reports.
Contact Us
For security-related inquiries:
Email: admin@rev-stay.com