Security at Aiterava
Enterprise-grade security for hospitality professionals
We take the security of your data seriously. Here is an overview of the measures we have in place to keep your information safe.
Infrastructure Security
TLS 1.3 Encryption
All data in transit is encrypted using TLS 1.3, the industry's strongest transport security standard.
AES-256 at Rest
Data stored on our servers is encrypted using AES-256, the gold standard for data-at-rest protection.
Certified Cloud Providers
Our infrastructure runs on ISO 27001 and SOC 2 Type II certified cloud providers.
Network Isolation
Production environments are isolated using private VPCs, firewalls, and strict network access policies.
Access Control
Role-Based Access
Fine-grained permissions with roles at tenant and system level, following the principle of least privilege.
SSO & MFA
Single Sign-On via Keycloak with support for Multi-Factor Authentication for all user accounts.
Audit Logs
All administrative and sensitive actions are logged with full audit trail for compliance and forensics.
Operational Security
DDoS Protection
Cloudflare-powered DDoS mitigation protects against volumetric and application-layer attacks.
Continuous Monitoring
24/7 monitoring with automated alerting for anomalous activity, intrusions, and performance issues.
Regular Backups
Automated daily backups with point-in-time recovery capability and geo-redundant storage.
Incident Response
A documented incident response plan ensures rapid containment, investigation, and disclosure.
Compliance
Aiterava is designed to help you comply with GDPR, African data protection regulations, and PCI-DSS for payment processing. We act as a data processor under a Data Processing Agreement (DPA) available on request.
Responsible Disclosure
Found a security vulnerability? Please report it responsibly to security@aiterava.com. We aim to acknowledge reports within 48 hours and resolve critical issues within 14 days.