Security & trust

Your data is isolated bythe database, not by our code.

Every claim on this page is something we can show you the same day. The section near the bottom lists what we do not have — because you will find it anyway, and it should come from us.

Isolation enforced by the database, not by our code

Hotel-scoped data is protected by Postgres Row-Level Security as well as application access checks. Restricted database roles enforce tenant boundaries; privileged operator and system operations are handled separately. This adds a layer of protection, not a guarantee that software can never have a security defect.

Enforced in production since August 2026. Every service connects with a restricted role that cannot bypass the policy and cannot change the schema.

We never hold a card number

The platform is designed to store payment-provider references, card brand and last four digits, not full card numbers. Recording a payment in a folio is different from processing a card; payment-provider availability must be confirmed for your setup.

Never enter card numbers into booking notes or send them to support. Payment tokens and integration credentials are treated as sensitive data.

Two-factor authentication for hotel accounts

RevioLink, RevioCRS and RevioPMS support authenticator-app codes and recovery codes. Enable two-factor authentication for your account and keep recovery codes somewhere safe. The operator console also supports two-factor authentication.

A second factor is checked during sign-in for enrolled accounts. Availability does not mean every staff member has enabled it.

Passwords nobody at Revio can read

Passwords are hashed, never stored or recoverable. When you need a reset, you set the new one yourself through a one-time link — we never learn it, and we never ask for it.

Support will never ask for your password. If anyone claiming to be us does, it is not us.

Sessions you can end from anywhere

Changing your password signs out every other device immediately, and “sign out everywhere” does it on demand — across every Revio product you run, because the identity is shared.

Verified at runtime: a live session stops working the moment it is revoked, not when it expires.

Backups, with a restore we have actually timed

Nightly encrypted backups. More importantly, we have restored from one and measured how long it took — about a minute — because an untested backup is a hope, not a control.

Restore drill run August 2026 and documented, including what it found.

Integration credentials encrypted, and never shown to a hotel

Channel and payment credentials are encrypted at rest. The operator console that holds them is a separate application on a separate login, and hotel accounts cannot reach it at all.

Operator business data lives in a schema hotel connections have no read access to.

Every product, one identity, one place to revoke it

A staff member who leaves is deactivated once and loses access to distribution, reservations and operations at the same moment — not three times in three systems, with one forgotten.

Account status is re-checked on every request, not just at sign-in.

Data you can take with you

Reservations, guests and reports export to CSV whenever you want, and on request we will produce a full export of your data. Leaving is a decision, not a hostage negotiation.

Export is a normal feature in the product, not a favour arranged during a cancellation.

A broken change never reaches your hotel

Every change runs our automated checks first — including ones written after real incidents, like money that cannot be read or a channel shown healthy without being measured. Only a version that passed all of them is deployed; a failing one simply stops, and the last good version keeps serving.

Scheduled jobs are monitored for having actually run, and backups are restored in rehearsal, not assumed.

GDPR, said plainly

Who is the controller of what

Your guests’ data is yours — we only ever act on your instruction. Your staff accounts are our customer relationship, so we are the controller for those. Claiming to be the processor for everything would be simpler, and wrong.

We are the processor

Guest data (reservations, guest profiles, stay history, folios)

The hotel is the controller. We process it only to run the service, on the hotel’s instructions, and we never use it for our own purposes — no profiling, no resale, no training on it.

We are the controller

Hotel staff accounts (names, work email, role, login and audit records)

This is our own customer relationship — we decide the retention, the security controls and the audit trail, so we are the controller for it.

We are the controller

Website visitors and demo enquiries

What you submit on this site, plus analytics you consented to. Ours, and deleted on request.

The full terms are in our data processing agreement, which we will sign as part of your contract.

Who else touches it

Our sub-processors, all of them.

If a company can hold or transit your data, it is on this list — including where the exposure is small. An incomplete list would be a breach of the agreement we are asking you to sign.

CompanyWhat it is forWhat it can seeWhere
RailwayApplication hosting, the Postgres database and object storage for uploaded imagesAll service data at rest and in transit — this is where the platform runs.United States (Virginia), under the EU Standard Contractual Clauses — move to the EU (Amsterdam) in preparation
Channex.ioConnectivity to Booking.com, Expedia and other channelsAvailability, rates and restrictions, plus the reservation details a channel sends us — guest name and contact for the booking it produced. Never folio or payment data.European Union / United Kingdom
StripeCard guarantees on direct bookings, and card payments where a property enables themCard details, which go to Stripe directly from the guest’s browser and never reach our servers. We hold a token and the last four digits.Ireland / United States (EU Standard Contractual Clauses)
ResendTransactional email — booking confirmations, invitations, password resetsRecipient address and the contents of the message we send.United States (EU Standard Contractual Clauses)
Google Analytics 4Anonymous traffic analytics on this marketing website onlyWebsite visitors who accepted cookies. IP anonymisation on. Never any hotel or guest data — this is not loaded by the products.United States (EU Standard Contractual Clauses)

We notify customers before adding a sub-processor. The current list also lives at /subprocessors.

Found something?

Tell us. We will thank you.

Report a vulnerability to security@reviosoft.app. We will acknowledge within one business day and tell you what we are doing about it.

We will not threaten anyone who reports a genuine issue in good faith. Please do not test against a live hotel’s data — ask us and we will give you something safe to test against.

WEBER BG EOOD · EIK 205090014 · 6 Preslav St, Ruse 7002, Bulgaria