Security & trust
Hotel financial data deserves enterprise-grade security.
How Innrly protects every invoice, folio, payroll record, and bank deposit — across every property in your portfolio.
How we protect your data.
Encryption everywhere
TLS 1.2+ in transit. AES-256 at rest on every data store, backup, and replica.
Identity & access
SSO (SAML/OIDC), enforced MFA, scoped roles per property and per module.
Full audit trail
Every login, change, and export is recorded with actor, time, and source IP — exportable for SOC 1 / SOX review.
Encrypted backups
Encrypted daily backups with point-in-time recovery across geographically separate regions.
Tier-1 infrastructure
Hosted on a top-tier cloud provider with isolated tenants, network segmentation, and DDoS protection.
24/7 monitoring
Continuous logging, anomaly detection, and a documented incident response plan with defined SLAs.
Vendor management
Every sub-processor reviewed for security, confidentiality, and data residency before going live.
Responsible disclosure
Coordinated disclosure program. Report vulnerabilities to security@innrly.com — we respond within one business day.
What security teams ask us.
Where is data hosted?
Innrly runs on a tier-1 US cloud provider with multi-region replication and isolated tenant storage. Data residency can be discussed for enterprise portfolios.
What compliance frameworks do you map to?
Our controls are aligned with SOC 2 and PCI-DSS principles. We share our security documentation under NDA — email security@innrly.com.
How do you handle PII?
Guest PII stays within the PMS unless explicitly required. Innrly minimizes the PII surface and never sells or shares your data with third parties.
Can I get a custom DPA or BAA?
Yes. We sign standard data processing agreements and accommodate enterprise legal review on request.
Have a security question or need our documentation? Email security@innrly.com or read our security overview.
Need our security pack?
SOC 2 mapping, sub-processor list, and DPA template — available under NDA.