Security
Built to be trusted with your office
How we protect your organisation's data, and how to report a security issue.
How we protect your data
Separated by organisation
Every organisation's data is scoped at the data layer: each query is limited to the organisation it belongs to, and automated tests prove one organisation can never read or change another's.
Encrypted in transit
All traffic uses TLS certificates, and plain HTTP is redirected to HTTPS. Each organisation is served on its own address, and session cookies never leave it.
Secure sign-in
Passwords are stored only as salted scrypt hashes. Sign-in and password reset are rate limited. Google and Microsoft sign-in only links to accounts whose email the provider verified.
Hardened servers
Hosted in the European Union. Operating system security updates install automatically, a firewall allows only web and SSH traffic, and server access requires cryptographic keys.
Controlled releases
Nobody edits production by hand. Every change passes formatting, type checks, linting and a build, then deploys through an automated pipeline followed by health checks.
Least privilege
Only named people who need it can reach production. Organisation administrators manage only their own organisation.
Privacy and compliance
GDPR
We act as processor for your workspace data under our Data processing agreement, which applies to every customer automatically.
EU hosting
Your data is stored in the European Union. Sub-processors are listed in our Privacy policy and changes are announced 30 days ahead.
No selling, no tracking
We do not sell data, show ads or use analytics cookies, and we do not train AI models on your data.
Report a vulnerability
We welcome reports from security researchers and customers.
Email security@booking-desks.com with a description of the issue, the steps to reproduce it, and its potential impact. We acknowledge reports within two business days and keep you informed until the issue is fixed.
While investigating, please:
- use only accounts and organisations you own or have permission to test;
- do not access, change or delete other people's data, and stop once you have shown the issue;
- do not run denial-of-service, spam or social engineering tests;
- give us reasonable time to fix the issue before disclosing it publicly.
We will not take legal action against research carried out in good faith within these rules, and with your permission we will credit you once the fix is released.
Security questionnaire or DPA for your procurement team? Write to us via the Contact page.