Trust & security

Your client book is your business. We treat it that way.

Travel businesses run their client relationships through TripOS. This page says plainly how we protect that — and just as plainly, what we don't claim.

Tenant isolation, enforced in the data layer

Every workspace-scoped query runs through membership checks on the server — not hidden UI. Cross-tenant requests return not-found, so workspace existence is never leaked. Roles (owner, admin, advisor, viewer) gate every administrative action.

Your content is not training data

We don't train models on your content — ours or anyone else's — and we don't sell it. Generation calls go to our model provider via API, which does not use API data for training. A deterministic pipeline handles generation when the model path is unavailable.

Encryption everywhere it matters

TLS for every connection; encryption at rest via our managed database provider. Partner API keys are stored as SHA-256 hashes and shown exactly once. Card details go straight to Stripe and never touch our servers.

Audit trail in every workspace

Member changes, role changes, branding updates, client operations, deliverable sends, API key lifecycle, and billing events are logged per workspace and visible to admins in the console.

Least-privilege access

Sessions are JWT-based with server-side authorization on every request. Rate limiting (per user, per key, per IP) guards generation, invites, and public endpoints. Client deliverable links are unguessable tokens that you can expire or revoke.

Boring, managed infrastructure

TripOS runs on Vercel with a managed PostgreSQL database, error monitoring via Sentry, and no self-managed servers to patch. Deploys are atomic and roll back cleanly.

Compliance, honestly

  • GDPR: data-subject rights are supported in-product (export, deletion, workspace controls); a DPA with Standard Contractual Clauses is available on Agency and Enterprise plans. See the DPA.
  • PCI: payments are processed entirely by Stripe (PCI DSS Level 1). TripOS never stores card data.
  • SOC 2: we are not SOC 2 certified today. We won't badge-wash — certification is on our roadmap, and Enterprise customers can request our current security practices in writing.

Your controls

  • Delete your account (Settings) or your workspace (console) — the data goes with it, subject to a 30-day backup rotation.
  • Revoke deliverable links, API keys, and member access at any time; every revocation is audit-logged.
  • Export itineraries as web links, print-ready PDF, and .ics — your work is never locked in.

Report a vulnerability

Found something? Email security@tripos.dev. We acknowledge reports within 2 business days and won't pursue good-faith research.

Questions your security team wants answered?

Talk to us