SECURITY
How we treat the data.
A travel business runs on customer trust: passports, payments, itineraries, the client list itself. These are the rules the product is built to — enforced in code, not promised in a PDF.
- 01
The backend is the bouncer
Permissions are enforced server-side on every request. The interface reflects your access; it never grants it.
- 02
Record-level access
Staff see the records their work requires — scoped by role and by file, not an all-or-nothing login.
- 03
Everything leaves a trail
Reads, writes, exports, denials — timestamped and owned. When something moves, you can see who moved it.
- 04
Documents live in private storage
Customer documents and payment evidence sit in private storage, tied to their booking — not in inboxes, not on desktops, not on someone's phone.
- 05
Mass export is a permission, not a default
Bulk downloads and exports are controlled and logged. Walking out with the client list should be hard, and visible.
- 06
Encrypted in transit and at rest
Data moves over TLS and sleeps encrypted. Table stakes, stated anyway.
- 07
Security that staff don't route around
If protection makes daily work slower than a spreadsheet, people go back to the spreadsheet — and that is the real breach. Controls are designed to stay out of the way.
Found something? Write to acceleret.official@gmail.com and a human will answer. Formal certifications will be published as the product moves through production.