Security

Last updated: September 21, 2026

Hotels trust Anfigo with their guests' conversations and with access to their PMS and payment accounts. This page describes how that is protected today. It is part of our Data Processing Addendum (Annex II).

Where it runs

Anfigo runs on Google Cloud in the United States: the application on Cloud Run, the database on Firestore, files on Cloud Storage. Google encrypts all of it at rest. Every connection — the dashboard, the platforms' webhooks, the calls to your PMS — uses TLS.

Each property sees only its own data

Every record belongs to one property and is stored under it. Every dashboard request carries a signed session token, and the server checks that the property it asks about is the one the session belongs to. Hotels can split access into a Manager door (protected by a PIN) and a Front desk door, and the server — not only the screen — refuses the manager's pages to the front desk.

Sign-in and secrets

  • Passwords and PINs are stored only as salted one-way hashes (bcrypt). Google sign-in is available.
  • Repeated wrong sign-in attempts are slowed down, and wrong PINs are limited per property.
  • Integration credentials you give us (PMS keys, channel tokens, payment keys) are never shown back in the dashboard; forms show only that a value is saved.
  • The service's own secrets are held in Google Secret Manager, not in code.

Messages coming in

Every webhook is authenticated before it is read: Meta's request signatures, per-property secret URLs for WhatsApp connections, the PMS's shared secret, the payment provider's signature. Each delivery is processed exactly once, so a retried webhook never sends a guest a second answer or records a payment twice.

The AI and your bookings

  • We use only paid AI services, whose terms say your data is not used to train their models. We never train models on your data.
  • The assistant can change, cancel or refund a booking only if you switched that on. Before any automatic change it reads the booking fresh from your PMS, and it never cancels a booking a person on your team confirmed, took a payment on, or checked in.
  • Everything the assistant does to a booking is written into the chat's timeline for your team.

Backups and recovery

The database has point-in-time recovery for the last 7 days, daily backups kept 30 days and weekly backups kept 12 weeks. Deleted media can be recovered for 30 days. Restoring a property from a backup has been rehearsed. Backups are never restored into the service without a reason, and expire on their fixed schedule.

Monitoring

We are alerted on server errors, rejected webhooks, failed message deliveries, failed background tasks and downtime. Every log line carries the request and property it belongs to, so an incident can be traced.

Deletion

A guest's chat or a whole property can be erased on request (see data deletion). When a property leaves, data read from its PMS is deleted within 10 days and everything else within 30 days after the export window.

If something goes wrong

If a breach affects a property's data, we tell the property without undue delay and within 72 hours, with what we know and what we are doing about it.

Report a vulnerability

Write to security@anfigo.com with the details. Please do not access other customers' data, disrupt the service or publish the issue before we have fixed it. We reply, keep you informed and credit you if you wish.