unifystays
SecurityPublic beta security overview

How UnifyStays Protects Supplier Credentials and Account Data

UnifyStays treats supplier credentials as server-side secrets. Credentials are encrypted before database storage, scoped to the owning organization and environment, and never intended for browser-side exposure. Application API keys resolve the organization before supplier connections are selected for a request.

Credential protection

Supplier secrets are accepted through authenticated server actions and encrypted before persistence. Stored credential records contain encrypted material and encryption metadata rather than plaintext supplier keys.

Organization and environment isolation

Supplier connections and encrypted credentials are scoped to an organization and environment. Sandbox and production are separate trust boundaries, and credentials should not be moved between those contexts.

Operational logging

Request and booking logs are intended to expose identifiers, timing, states and safe diagnostic context. Secrets must be redacted from application logs, client payloads and support views.

Responsible disclosure

If you believe you have found a security issue, do not include live credentials or customer data in the report. Contact security@unifystays.com with reproduction details and an impact summary.

Frequently asked questions

Are supplier credentials stored in plaintext?+

No. The product encrypts supplier credential payloads before storing them.

Can sandbox credentials be used in production?+

They should not be. Environment is part of the credential and connection boundary.

Where should I report a security issue?+

Email security@unifystays.com without including live secrets or unrelated customer data.

Free public beta

Build one hotel integration that can grow with your supply.

Create an organization, issue an API key and configure an available supplier connection without a sales call.

Create beta account →Contact the team