Trust Center

Your data is safe with us

We take security, privacy, and reliability seriously. Here’s exactly how we protect your business data and your clients’ information.

Security practices

🔒

Data encryption

All data is encrypted in transit using TLS 1.3. Data at rest is encrypted using AES-256 on Neon PostgreSQL. We never store plaintext sensitive data.

🗄️

Infrastructure

Database hosted on Neon PostgreSQL with automated backups and point-in-time recovery. Media assets stored on Cloudflare R2 with zero-trust access controls.

🌐

CDN & DDoS protection

All Travesy traffic is routed through Cloudflare's global CDN. DDoS mitigation and bot protection are enabled at the network layer.

🔑

Authentication

Passwords are hashed using bcrypt with a salt factor of 12. Session tokens are cryptographically signed. We support optional 2FA for Pro and Agency accounts.

🛡️

Portal security

Individual portals can be protected with passwords. Expiry dates ensure stale proposals don't stay live. Access logs show every portal view.

🔍

Security monitoring

We monitor for unusual access patterns, brute-force attempts, and injection attacks 24/7. Critical alerts are responded to within 1 hour.

Compliance & data practices

GDPR-aligned

We align with GDPR principles — lawful basis for processing, data minimisation, and right of deletion. EU-based users can request data export or deletion at any time.

AI provider transparency

Our AI content writer uses Claude (by Anthropic). Content submitted for generation is processed by Anthropic's API and subject to their privacy policy. We do not use AI outputs to train our own models.

Data residency

Primary database (Neon PostgreSQL) is hosted with regional replicas. Media assets (Cloudflare R2) may be cached globally at Cloudflare edge nodes for performance.

99.9% uptime commitment

We monitor Travesy and all client portals 24/7. Our infrastructure is designed for high availability with automatic failover. Planned maintenance is communicated in advance.

99.9%
Target uptime
24/7
Monitoring
< 1 hour
Incident response

What data we handle

What we store

Account information (name, email, agency)
Trip data you create (itineraries, hotel info, descriptions)
Client portal view analytics (anonymised)
Payment records (processed by Stripe or Razorpay — we never store card numbers)
Support communication history

What we don't store

Client credit card numbers (handled by Stripe/Razorpay)
Passwords in plaintext (bcrypt-hashed only)
Personal data of your clients beyond what you enter
Data for advertising or resale of any kind
🔐

Security disclosures

If you discover a security vulnerability in Travesy, please report it responsibly. We take all reports seriously and will respond within 24 hours.

security@travesy.com →

PGP key available on request.