Hotels trust Anfigo with their guests' conversations and with access to their PMS and payment accounts. This page describes how that is protected today. It is part of our Data Processing Addendum (Annex II).
Anfigo runs on Google Cloud in the United States: the application on Cloud Run, the database on Firestore, files on Cloud Storage. Google encrypts all of it at rest. Every connection — the dashboard, the platforms' webhooks, the calls to your PMS — uses TLS.
Every record belongs to one property and is stored under it. Every dashboard request carries a signed session token, and the server checks that the property it asks about is the one the session belongs to. Hotels can split access into a Manager door (protected by a PIN) and a Front desk door, and the server — not only the screen — refuses the manager's pages to the front desk.
Every webhook is authenticated before it is read: Meta's request signatures, per-property secret URLs for WhatsApp connections, the PMS's shared secret, the payment provider's signature. Each delivery is processed exactly once, so a retried webhook never sends a guest a second answer or records a payment twice.
The database has point-in-time recovery for the last 7 days, daily backups kept 30 days and weekly backups kept 12 weeks. Deleted media can be recovered for 30 days. Restoring a property from a backup has been rehearsed. Backups are never restored into the service without a reason, and expire on their fixed schedule.
We are alerted on server errors, rejected webhooks, failed message deliveries, failed background tasks and downtime. Every log line carries the request and property it belongs to, so an incident can be traced.
A guest's chat or a whole property can be erased on request (see data deletion). When a property leaves, data read from its PMS is deleted within 10 days and everything else within 30 days after the export window.
If a breach affects a property's data, we tell the property without undue delay and within 72 hours, with what we know and what we are doing about it.
Write to security@anfigo.com with the details. Please do not access other customers' data, disrupt the service or publish the issue before we have fixed it. We reply, keep you informed and credit you if you wish.