Trust center
Trust that matches how the product works
We describe controls that exist today. We do not use empty slogans about “military-grade” or “bank-grade” security.
Account security
Sign-in and recovery use the platform’s secure authentication. Password-reset messages go to the account email.
Data isolation
Each guide workspace keeps its own data. Access is checked on the server for every sensitive action — hiding a button in the interface is never enough.
Access control
Roles and memberships decide who can see and change operational data. Platform support tools, when used, follow a separate audited path.
Public and private content
Only published site content is visible to travelers. Drafts and unpublished changes stay inside the workspace until you publish.
Data ownership
Your brand, contacts and operational records remain yours. Workspace owners can export a bounded, audited snapshot of their data.
Privacy
We minimize what we store and avoid putting personal details into analytics or marketing events. Message bodies are never logged for marketing.
Technical details for reviewers
Workspace isolation and permissions are enforced server-side for every sensitive operation. URLs and forms may carry a workspace selector; that selector never replaces authorization. Public guide sites only serve published snapshots.