---
title: Hotel PMS Security, Permissions & Audit Trail | bedsKey
description: Row-level tenant isolation, multi-property, granular role-based permissions, append-only audit trail, Argon2id, AES-256-GCM and real-time sync.
canonical: https://bedskey.com/features/security/
updated: 2026-10-03
publisher: bedsKey (Innovate Solution)
---


# Multi-tenant platform, security and reliability

Enterprise-grade foundations for 10 hotels today and 200+ tomorrow.

**In short:** Row-level tenant isolation, multi-property, granular role-based permissions, append-only audit trail, Argon2id, AES-256-GCM and real-time sync.

Updated October 2026

## What Platform & Security does

- **Multi-tenant isolation** — each hotel group’s data is isolated at the database level with row-level security.
- **Multi-property** — a group runs several properties under one account, with per-property settings and group reporting.
- **Advanced role-based access (RBAC)** — granular per-action permissions and custom roles; a user can be Manager at one property and Receptionist at another.
- **Sensitive-action controls** — rate overrides, discounts, voids, refunds and folio adjustments can require an authorised user.
- **Audit trail** — every change recorded with who, what, where and when, including field-level before/after values; append-only.
- **Real-time sync** — WebSocket push updates every open screen instantly.
- **Security** — Argon2id password hashing, JWT sessions with revocation, AES-256-GCM for identity documents, rate limiting.
- **System Health monitoring** — service status, background jobs, queues, card-hold countdowns and outbound delivery.
- **Database Health monitoring** — connection pool, slow queries, index and table health, and guided integrity checks.
- **Cloud-hosted** — nothing to install; works in any modern browser; managed PostgreSQL with automated backups.

## Works with

### [Reservations & ARI](https://bedskey.com/features/reservations/)

See every room, every night, in one grid. The heart every other module relies on.

### [Folio & Night Audit](https://bedskey.com/features/billing-night-audit/)

Every charge, tax and payment on one clean statement — with exact decimal arithmetic.

### [Partner API](https://bedskey.com/features/partner-api/)

Let agents and partners search and book you directly through a secure API.

## Technology stack

| Layer | Technology |
| --- | --- |
| Backend | Go 1.25 — compiled, concurrent, low memory footprint |
| Database | PostgreSQL 18 with exclusion constraints for guaranteed no-overlap bookings and row-level security |
| Money | Exact decimal arithmetic end to end — no floating-point rounding |
| Cache & sessions | Redis — token revocation, permission cache, rate limiting |
| Web frontend | React 19, TypeScript, Vite, TanStack Query, Tailwind CSS |
| Mobile | Flutter — three iOS and Android apps on one shared core |
| Real-time | WebSocket |
| Edge | Caddy reverse proxy with automatic TLS |

## Platform & Security: common questions

### How is each hotel’s data isolated?

Each hotel group’s data is isolated at the database level with PostgreSQL row-level security.

### Does bedsKey keep an audit trail?

Yes. Every change is recorded with who, what, where and when, including field-level before and after values, in an append-only log.

### Do I need to install bedsKey?

No. bedsKey is cloud-hosted, works in any modern browser and runs on managed PostgreSQL with automated backups.

## Related guides

- [Cloud vs on-premise PMS](https://bedskey.com/compare/cloud-vs-on-premise-pms/)
- [What is a hotel PMS?](https://bedskey.com/glossary/pms/)

## Run your entire property from one system.

Talk to sales@bedskey.com — we’ll walk you through bedsKey with your own rooms and rates.
