Security at Aiterava

Enterprise-grade security for hospitality professionals

We take the security of your data seriously. Here is an overview of the measures we have in place to keep your information safe.

Infrastructure Security

🔒

TLS 1.3 Encryption

All data in transit is encrypted using TLS 1.3, the industry's strongest transport security standard.

💾

AES-256 at Rest

Data stored on our servers is encrypted using AES-256, the gold standard for data-at-rest protection.

☁️

Certified Cloud Providers

Our infrastructure runs on ISO 27001 and SOC 2 Type II certified cloud providers.

🔐

Network Isolation

Production environments are isolated using private VPCs, firewalls, and strict network access policies.

Access Control

👤

Role-Based Access

Fine-grained permissions with roles at tenant and system level, following the principle of least privilege.

🔑

SSO & MFA

Single Sign-On via Keycloak with support for Multi-Factor Authentication for all user accounts.

📋

Audit Logs

All administrative and sensitive actions are logged with full audit trail for compliance and forensics.

Operational Security

🛡️

DDoS Protection

Cloudflare-powered DDoS mitigation protects against volumetric and application-layer attacks.

🔍

Continuous Monitoring

24/7 monitoring with automated alerting for anomalous activity, intrusions, and performance issues.

🔄

Regular Backups

Automated daily backups with point-in-time recovery capability and geo-redundant storage.

Incident Response

A documented incident response plan ensures rapid containment, investigation, and disclosure.

Compliance

Aiterava is designed to help you comply with GDPR, African data protection regulations, and PCI-DSS for payment processing. We act as a data processor under a Data Processing Agreement (DPA) available on request.

Responsible Disclosure

Found a security vulnerability? Please report it responsibly to security@aiterava.com. We aim to acknowledge reports within 48 hours and resolve critical issues within 14 days.