Skip to content

Security and data

What is true today, and what is not.

Bookesto is pre-launch. This page states what is implemented, what is not started, and what has to happen before each item changes. There are no badges on this page.

Implemented and verified in the build

Tenant isolation
PostgreSQL row-level security, forced, on 105 tables — enforced by the database, not by application code
Privilege separation
Separate database roles for the application runtime, authentication, and schema ownership
Concurrency safety
A database exclusion constraint makes overlapping bookings on one resource impossible, independent of application logic
Verification
Six database integration tests assert isolation; the full suite runs in continuous integration on every change
Transport and storage
TLS in transit and encryption at rest — stated for the local build; re-stated with evidence when production exists
Payments
Card data never reaches our servers. Stripe handles it, on your own account
Customer funds held
None. Ever. By architecture

Distinct ALTER TABLE … FORCE ROW LEVEL SECURITY statements in packages/db/prisma/migrations · counted 2026-08-17

Not started, and we are not going to imply otherwise

Security and compliance items that are not in place, with the trigger that changes each one
ItemStatusWhat changes it
SOC 2 Type I or IINot startedBegins after the first 100 paying merchants
ISO 27001Not startedNot planned before SOC 2
EU data-protection compliance claimNot claimableRequires an Article 27 representative, a DPA with standard contractual clauses, and EU-region hosting. All three pending. EU signups are gated until then
PCI DSSNot applicable to usStripe is assessed; we are not the entity being assessed. Card data does not touch our servers
Uptime SLANo operating historyThere is no production deployment. An SLA without history is a fabrication
Public status pageNot publishedShips when production is real, and will show real incidents
Penetration testNot commissionedBefore private beta

If you need a completed security questionnaire, a signed DPA or a pen-test report before you can buy, we do not have them yet. Saying so now is cheaper for both of us than saying so after a procurement review.

Who else touches the data

Third parties that process data on our behalf
SubprocessorPurposeDataRegion
Hetzner Online GmbHHosting and backupsAll application dataGermany or Finland, stated per deployment
StripePayment processingPayment metadata. Card data never reaches BookestoIreland / United States, per Stripe's terms
360dialog GmbHWhatsApp Business API accessMessage content and phone numbers for WhatsApp onlyGermany
Meta Platforms IrelandWhatsApp message deliveryMessage content and phone numbers for WhatsApp onlyIreland

This list is complete as of . Adding a subprocessor requires prior notice, and we will publish the change on the changelog before it takes effect.

The subprocessor page, with the change-notification commitment

Your data, your exit

These are commitments about the service, not a description of a running one. There is no deployment and there are no accounts yet, so nothing below has been exercised by a customer.

Export
Will cover contacts, conversations, bookings, deposits and message history, as CSV and JSON, self-serve. Not built yet
Exit fee
None
Deletion
On request, with a stated retention period for legal and accounting records
Ownership
Your customers are yours. There is no cross-merchant directory and no cross-promotion
Lock-in
Your Stripe account and your WhatsApp Business account are registered to you and leave with you

Why we only use the official API

Unofficial WhatsApp gateways get business numbers permanently banned. Bookesto connects only through Meta's official Cloud API, through 360dialog, and there is no mode in which it does anything else — including in testing. This is a merchant-protection decision as much as a compliance one.

Found a problem

Email security@bookesto.com. Include enough detail to reproduce it. We will confirm receipt within two business days and tell you what we are doing about it. There is no bounty programme yet and we are not going to pretend there is.

Security questions

Where is the data hosted?
Hetzner, in Germany or Finland, with the region stated per deployment. EU-region hosting for EU tenants is part of the data-protection pack that is not yet complete.
Can I get a DPA?
Not yet. It is drafted for counsel review and it is on the roadmap. When it is signable, this page will link to it.
Who is the legal entity?
AL MANNAN GENERAL TRADING FZE-LLC, Sharjah, United Arab Emirates.
Do you train models on my data?
No. There is no customer-facing model runtime at all today, and if one is ever approved, training on customer data will not be part of it.

Status of this page checked