bedsKey FAQ · Security

Security, data & platform: questions and answers

In short: Each hotel group's data is isolated at the database level with row-level security. Staff get granular per-action permissions, sensitive actions can require an authorised user, and every change is recorded in an append-only audit trail. Passwords use Argon2id, identity documents use AES-256-GCM, and the managed database has automated backups.

11 questions · Updated October 2026 · bedsKey product team

Data isolation & access

How is my hotel's data kept separate from other hotels?

bedsKey is multi-tenant, and each hotel group's data is isolated at the database level with row-level security, so one tenant's queries cannot read another tenant's rows.

Can I control exactly what each staff member can do?

Yes. Role-based access control uses granular per-action permissions and custom roles, and a user can hold different roles at different properties.

Can discounts, voids and refunds require a manager?

Yes. Rate overrides, discounts, voids, refunds and folio adjustments can be set to require an authorised user.

Is there an audit trail?

Yes. Every change is recorded with who, what, where and when, including field-level before and after values. The trail is append-only, so entries cannot be edited or removed.

Security measures

How are passwords and sessions protected?

Passwords are hashed with Argon2id. Sessions use JWTs that can be revoked, and sign-in is rate-limited. On shared handsets, sessions live only in the device keystore.

How are identity documents protected?

Passport and national ID scans are encrypted with AES-256-GCM, viewing them needs a separate permission, every view is audited, and documents are deleted automatically after your retention period.

Does bedsKey handle card data?

No. Card payments are taken on the payment gateway's own page, so card numbers never reach bedsKey.

Reliability & technology

Is my data backed up?

Yes. bedsKey runs on managed PostgreSQL with automated backups.

How does bedsKey keep every screen up to date?

Real-time sync over WebSocket pushes every reservation, room-status and folio change to every open screen the moment it happens, so reception, housekeeping and managers see the same picture.

How is the platform monitored?

System Health monitoring covers service status, background jobs, queues, card-hold countdowns and outbound delivery. Database Health monitoring covers the connection pool, slow queries, index and table health, with guided integrity checks.

What technology is bedsKey built on?

A Go backend; PostgreSQL 18 with exclusion constraints and row-level security; exact decimal arithmetic for money; Redis for token revocation, permission cache and rate limiting; a React and TypeScript web app; Flutter for the iOS and Android apps; WebSocket for real-time updates; and a Caddy edge with automatic TLS.

Didn’t find your answer?

Ask the team directly. We reply from sales@bedskey.com, and a demo uses your own rooms and rates.

Run your entire property from one system.

Talk to sales@bedskey.com — we’ll walk you through bedsKey with your own rooms and rates.