Trust · Security

Saudi data, in Saudi Arabia, secured at every layer.

Your property data, your guest records and your financial books sit on infrastructure inside the Kingdom, encrypted at rest and in transit, with role-based access control and a full audit log. Here is the detail.

Trust is what hotel groups and investor-backed operators evaluate us on before functionality. We treat it that way. The detail below covers infrastructure, data handling, access control, regulatory compliance and incident response. If you need additional artefacts for a procurement review (SOC 2 readiness, custom DPA, infra diagram), email security@taskyinn.sa and we will engage directly.

How we protect your data

01

Data residency in Saudi Arabia

Your tenant database, file storage and backups all sit on infrastructure inside the Kingdom. We do not replicate guest or financial data outside Saudi Arabia.

  • Primary database and object storage in-Kingdom
  • Daily encrypted backups retained in-Kingdom
  • No cross-border replication of guest or financial records
02

Encryption at rest and in transit

Every connection to Taskyinn — web app, API, mobile — is enforced over TLS 1.2+ with HSTS. Sensitive data fields (national ID, Iqama, passport, payment tokens) are encrypted at rest. Database volumes are encrypted with managed keys.

  • TLS 1.2+ enforced; HSTS on every domain
  • AES-256 at rest for database and object storage
  • PII fields (ID, payment tokens) double-encrypted at the application layer
03

Role-based access control

Every Taskyinn role has a precisely scoped permission set against the Hasura GraphQL schema with row-level security on every table. A receptionist cannot see the GL, an accountant cannot edit reservations, and a tenant admin cannot see another tenant’s data — at the database level, not just the UI.

  • Row-level security enforced at the database layer
  • Per-property and per-tenant isolation by JWT claim
  • Granular roles: receptionist, GM, accountant, HK, owner, admin, …
  • SSO-ready (SAML / OIDC) on Enterprise plans
04

Audit logs

Every write — reservation change, folio posting, GL journal, permission change, invoice issuance — is logged with the user, timestamp, IP and the before/after snapshot. Logs are retained for the regulator’s minimum and exportable on request.

  • Reservation, folio and GL change audit log
  • Permission and user-management audit log
  • Login / impersonation / session log retained 12+ months
05

Backups and disaster recovery

Daily encrypted backups with point-in-time recovery up to 7 days. Quarterly recovery drills against a separate environment. Recovery objective: RTO 4 hours, RPO 1 hour.

  • Daily encrypted backups, retained 30 days
  • Point-in-time recovery up to 7 days
  • RTO 4 hours / RPO 1 hour
06

Incident response

A documented incident-response process with named owners, severity classification, communication templates for affected tenants and post-incident review. Security disclosures: security@taskyinn.sa.

  • Documented severity matrix and on-call rotation
  • Tenant-facing notification within regulatory timelines
  • Public post-mortem for any sev-1 incident affecting customer data

Regulatory & certification status

The regulators that matter for a Saudi PMS — and where we stand against each.

ZATCA Phase-2 e-invoicingCertified

Listed Phase-2 e-invoicing service provider. UBL 2.1 XML, cryptographic signature, QR code, real-time clearance/reporting.

PDPL (Saudi Personal Data Protection Law)Compliant

Data residency, consent records, subject-access workflow, DPO contact: privacy@taskyinn.sa.

Ministry of Interior — ShomoosIntegrated

Auto-registration of every guest at check-in; locked identity fields for already-verified guests.

Ministry of Tourism — NTMPIntegrated

Nightly occupancy reporting submitted automatically. Rooms-scope only; POS lines are out of NTMP scope.

SAMA — payment partnersApproved partners only

Mada, Apple Pay, STC Pay, Visa, Mastercard, Tamara and Tabby — all SAMA-licensed.

SOC 2In progress

Type-1 readiness work underway 2026; target report 2027. Available on the Enterprise plan when ready.

Talk to our security team

For procurement reviews, DPAs, infrastructure diagrams or to report a vulnerability, write to:

security@taskyinn.sa
Trust matters before functionality

Walk our security posture before you sign.

We will share the artefacts your procurement team needs and answer the questions your CISO will ask.