Security & reliability
Security and reliability,by design
Trip Zen’s cloud platform is designed around secure access, encrypted connections, monitoring, and backups, so your business can rely on booking infrastructure it does not have to operate itself.
Principles
Eight principles behind the platform
How the platform is designed and operated. Commitments specific to your business are defined in your licensing agreement.
Secure authentication
Access to the platform requires authenticated user accounts, with access removed when users are disabled.
Access control
Role-based, user-level, and organization-level permissions limit each person to the data and actions their work requires.
Encrypted connections
Traffic between users, the platform, and connected services is designed to travel over encrypted connections.
Infrastructure monitoring
Cloud infrastructure is monitored so issues can be detected and acted on.
Backup strategies
Backup infrastructure and strategies are designed to protect platform data against loss.
Data protection
Customer data is handled within the platform environment, separated by organization, and governed by your licensing agreement.
System availability
Centralized, scalable cloud infrastructure is designed to keep the platform available as usage grows.
Operational monitoring
Platform operations and integrations are monitored so problems can be investigated promptly.
In practice
What each area covers
A closer look at how the platform approaches each area. Documentation for your own review can be discussed during evaluation.
Authentication & access control
Everyone who works in the platform signs in to a user account, and permissions decide what each account can see and do.
In practice
- User accounts created, assigned roles, and disabled by your administrators
- Role-based, user-level, and organization-level permissions
- Teams and administrative controls for managing access at scale
Encrypted connections
Connections between people, the platform, and connected services are designed to be encrypted in transit.
In practice
- Browser access to the platform designed for encrypted connections
- Supplier and payment provider connections designed for encrypted transport
- API access designed around authenticated, permissioned connections
Infrastructure monitoring
The cloud infrastructure beneath the platform is monitored so issues can be detected and acted on.
In practice
- Centralized cloud infrastructure rather than servers run by each customer
- Software updates delivered centrally through automated deployment
Backups
Backup infrastructure and backup strategies are part of the platform design, to protect platform data against loss.
In practice
- Backup infrastructure provided as part of the cloud platform
- No platform backup servers for your team to run
Data protection
Customer data is handled within the platform environment and governed by your licensing agreement and our legal policies.
In practice
- Organization-level access controls designed to keep each customer’s data and configuration separate
- Customer-owned data, content, and branding remain yours, depending on your contract
- Data handling described in the Privacy Policy and Licensing Terms
System availability
Centralized, scalable cloud infrastructure is designed to keep the platform available as usage grows.
In practice
- Scalable computing resources as users, products, and booking volume grow
- Remote access with no local installation for your team to maintain
- Dedicated infrastructure options can be scoped in an Enterprise agreement
Operational monitoring
Platform operations and integrations are monitored so problems can be investigated promptly.
In practice
- Oversight of platform operations and supplier integrations
- Support for your team according to your plan
Responsible disclosure
If you believe you have found a security vulnerability in Trip Zen, please report it privately to [email protected] so we can investigate before any details are made public.
When you report
- Include a clear description, the affected area, and steps to reproduce.
- Do not access, modify, or delete data that does not belong to you.
- Do not disrupt the platform or degrade the service for other users.
- Give us reasonable time to investigate and address the issue before disclosing it publicly.
Security reviews during evaluation
Security questionnaires and specific requirements can be discussed during evaluation. Share what your organization needs to review, and the Trip Zen team will tell you what can be provided.
Topics to raise
FAQ
Security questions
Common questions about access, data, and backups. For anything specific to your organization, talk to Sales.
Does Trip Zen hold security certifications?
This website does not list certifications. If your organization requires specific compliance documentation, raise it during evaluation and our team will tell you what can be provided.
Who can access our data in the platform?
Access is controlled through authenticated accounts and role-based, user-level, and organization-level permissions that your administrators manage.
Is data backed up?
The platform is designed with backup infrastructure and backup strategies to protect platform data.
Who owns the data we put into Trip Zen?
Customer business information, customer-provided content, customer branding, and customer-owned data remain yours, depending on your contract. See Licensing Terms and the Privacy Policy.
Are dedicated infrastructure options available?
Dedicated infrastructure options can be scoped as part of an Enterprise agreement. Talk to Sales.
Build on infrastructure you don’t have to run
Request a demo to see user management and access controls in the platform, and raise your security requirements during evaluation.
