Security & trust

Clear security information without invented claims.

Hospli stores operational records connected with hospitality venue readiness, so security and access control matter. This page explains the controls currently implemented in Hospli and distinguishes them from independent certifications that have not yet been obtained.

Authentication & access

Access is tied to authenticated users and organisations.

Passwordless authentication

Hospli uses secure email sign-in links rather than storing user passwords. Sign-in links expire after 15 minutes.

Database-backed sessions

Authenticated sessions are stored in the application database and linked to the signed-in user.

Organisation-scoped access

Organisation-level access is checked against the signed-in user's organisation membership before protected organisation data is returned.

Venue-scoped access

Protected venue access is checked against the organisation that owns the venue and the signed-in user's membership of that organisation.

Role-based billing controls

Billing changes are restricted to organisation owners and administrators.

Server-side secrets

Authentication, billing, email and storage credentials are loaded from server-side environment configuration rather than embedded in public application code.

Payments

Payments are handled through Stripe.

Hospli creates Stripe-hosted Checkout sessions for subscription payments and uses Stripe's hosted billing portal for subscription management.

Hospli does not collect or store payment card details in its own application.

Browser protections

Security headers are applied across the application.

Hospli applies browser security headers including protection against MIME-type sniffing and framing, a restrictive permissions policy, referrer controls and HTTPS transport enforcement.

Security controls are reviewed as the application evolves.

What Hospli does not claim

No certification badge without the certification.

Hospli does not currently claim ISO 27001 certification, Cyber Essentials certification, Cyber Essentials Plus certification, SIA approval or government security accreditation.

If independent certifications or security assessments are obtained in future, they will only be displayed once they are genuinely in place and their scope can be described accurately.

Responsible security

Security concerns can be reported directly.

If you believe you have identified a security issue affecting Hospli, please report it privately rather than publishing sensitive details before the issue can be investigated.

For organisations

Need security information for a group pilot?

Hospli can provide a clear description of its current product, authentication, access-control and payment architecture for organisations evaluating a pilot or wider rollout.