Credential protection
Supplier secrets are accepted through authenticated server actions and encrypted before persistence. Stored credential records contain encrypted material and encryption metadata rather than plaintext supplier keys.
Organization and environment isolation
Supplier connections and encrypted credentials are scoped to an organization and environment. Sandbox and production are separate trust boundaries, and credentials should not be moved between those contexts.
Operational logging
Request and booking logs are intended to expose identifiers, timing, states and safe diagnostic context. Secrets must be redacted from application logs, client payloads and support views.
Responsible disclosure
If you believe you have found a security issue, do not include live credentials or customer data in the report. Contact security@unifystays.com with reproduction details and an impact summary.
Frequently asked questions
Are supplier credentials stored in plaintext?+
No. The product encrypts supplier credential payloads before storing them.
Can sandbox credentials be used in production?+
They should not be. Environment is part of the credential and connection boundary.
Where should I report a security issue?+
Email security@unifystays.com without including live secrets or unrelated customer data.