RevStay
Legal_

Security & Compliance

Last Updated: April 18, 2026

Our Commitment to Security

At RevStay, security is foundational to everything we build. We handle sensitive guest data, payment information, and property management credentials—and we take that responsibility seriously. This page outlines our security practices and commitments to you.

Encryption at Rest

  • All sensitive credentials (PMS API keys, OAuth tokens) are encrypted using AES-256-GCM
  • Database hosted on infrastructure with automatic encryption at rest
  • Encryption keys are managed separately from application data

Encryption in Transit

  • All connections use TLS 1.2 or higher (TLS 1.3 preferred)
  • HTTPS enforced on all endpoints
  • HSTS headers prevent downgrade attacks

Authentication & Access Control

  • Authentication powered by Clerk, a SOC 2 Type II certified identity provider
  • Multi-factor authentication (MFA) available for all accounts
  • Session tokens validated on every request
  • Role-based access control for admin functions
  • Automatic session expiration and secure logout

Payment Security

RevStay never stores credit card numbers or sensitive payment data directly. All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor.

  • No card data touches our servers
  • Stripe handles all PCI compliance requirements
  • Webhook signatures verified cryptographically
  • Idempotency controls prevent duplicate charges

Infrastructure Security

Hosting

  • Application hosted on Vercel (SOC 2 Type II certified)
  • Database hosted on Neon (PostgreSQL with automatic encryption)
  • Geographic data residency in United States
  • Automatic backups with point-in-time recovery

Network Security

  • DDoS protection via edge network
  • Web Application Firewall (WAF) rules
  • Rate limiting on API endpoints
  • SSL/TLS termination at edge

Third-Party Integrations

We carefully vet all third-party services and only partner with providers that meet our security standards. All of our critical infrastructure providers are SOC 2 Type II certified, including:

  • Stripe (Payment Processing) – PCI DSS Level 1, SOC 2
  • Clerk (Authentication) – SOC 2 Type II
  • Twilio (SMS Delivery) – SOC 2, ISO 27001
  • Resend (Email Delivery) – SOC 2 Type II
  • Vercel (Application Hosting) – SOC 2 Type II
  • Neon (Database) – SOC 2 Type II

API Security

  • All API inputs validated using strict schemas
  • Rate limiting prevents abuse and brute force attacks
  • Webhook signatures verified on all incoming webhooks
  • CORS policies restrict cross-origin requests
  • SQL injection prevention via parameterized queries

Data Privacy & GDPR

  • Data minimization: We only collect what's necessary
  • Right to access: Users can request their data
  • Right to deletion: Accounts can be fully deleted
  • Data portability: Export your data anytime
  • Clear consent mechanisms for SMS marketing

For detailed information, see our Privacy Policy.

SMS Compliance (TCPA)

  • Explicit opt-in required before sending marketing messages
  • Easy opt-out via STOP keyword
  • Consent records maintained indefinitely
  • Message frequency controls
  • Clear identification of message sender

For detailed information, see our SMS Consent Policy.

Monitoring & Incident Response

  • 24/7 application monitoring
  • Automated alerting for anomalies and errors
  • Audit logging for sensitive operations
  • Incident response procedures documented
  • Regular security reviews of access logs

Business Continuity

  • Regular database backups
  • Point-in-time recovery available
  • Multi-region failover capabilities
  • High availability infrastructure

Security Questionnaires

We understand enterprise customers often require security assessments. We're happy to complete your security questionnaire or provide additional documentation. Contact us at admin@rev-stay.com with your requirements.

Responsible Disclosure

If you discover a security vulnerability, please report it responsibly to admin@rev-stay.com. We appreciate security researchers who help us keep our platform safe and will acknowledge valid reports.

Contact Us

For security-related inquiries:
Email: admin@rev-stay.com

SECURITY