Enterprise Security

Security & Compliance

Traffic is served over HTTPS, with HTTP redirected at the edge. Role-based access control determines what each member of staff can see and do, and data is separated per organization at the row level.

See how security enables our powerful features and learn about our company.

Last updated: February 2026

Data In Transit

Traffic is served over HTTPS, with HTTP redirected at the edge. We are not currently claiming encryption at rest or a minimum TLS version — our trust page sets out what is verified and what is not.

  • HTTPS everywhere, HTTP redirected at the edge
  • HSTS set on application responses
  • Passwords stored only as salted hashes
  • Secrets held in a managed secret store

Authentication & Role-Based Access

Granular role-based access control and short-lived sessions ensure only authorized users can access sensitive data.

  • Role-based access control (RBAC)
  • Short-lived server-side session tokens
  • Sign-in required at least every 30 days
  • Passwords stored only as salted hashes

Row-Level Security (RLS)

Data is separated per organization at the row level, so one customer's records are not reachable from another's session.

  • Property-level data isolation
  • Organization-level access controls
  • Tenant-level data segregation
  • Cross-property reporting with proper permissions

Audit Logging

Changes to financial ledger records and to signed documents are written to an append-only audit trail. That is the scope: there is not a complete audit trail of every action taken in the system, and we would rather say so than let a shorter sentence imply it.

  • Append-only history for ledger records
  • Append-only history for signed documents
  • Scoped to those two areas

Backups & Recovery

Automated backups with point-in-time recovery, and deletion protection on the database. Redundancy is across availability zones within a single United States region, not across regions.

  • Automated backups
  • Point-in-time recovery
  • Availability-zone redundancy in one US region
  • Restore last rehearsed 1 June 2026

Multi-Tenant Architecture

Data is separated per organization at the row level, so one customer's records are not reachable from another's session. No independent party has tested this; it is our own assessment of our own system.

  • Row-level data separation per organization
  • Scalable architecture
  • Performance optimization

Security Practices

What Room Choice actually has in place, and what it does not. We list only controls we can point at

Card data captured directly by Stripe, never transmitted through our servers
Role-based access control with row-level data isolation between organizations
Automated dependency, secret and static-analysis scanning on every change
Automated backups with point-in-time recovery; the last restore drill rebuilt the database but did not check row-level data integrity
Data held in a single United States region as at 31 August 2026, with no European or other regional option
Error reporting configured not to capture personal data or local variables, and to scrub sensitive fields before an error is recorded

Secure Integrations

We partner with industry-leading providers to ensure your data and payments are always secure

Stripe

Card details entered directly into payment fields hosted by Stripe

Plaid

ACH and bank account verification

Dropbox Sign

Enterprise-grade e-signature security and compliance

Questions About Security?

Room Choice is a small company; a question about our security posture is answered by the person who builds the system, which is why this page can be as specific as it is.

Schedule a Security Review