Tenant and property isolation

Tenant and property boundaries separate guests, reservations, rooms, billing, users and operational records between clients and properties.

Role-based access

Reception, management, administration and the platform have different permissions. MFA, recovery codes and step-up verification provide additional protection for sensitive actions.

Audit and Control of Sessions

Security and audit logs, session review and revocation, CSV exports and network allow/block rules give the team a record and a way to respond.

Data protection and life cycle

HTTPS transmission, controlled backups, secure records and automation for retention or anonymisation form part of the technical foundation. Exact retention periods and production use depend on the contract, legal basis and approved policy.

Evidence of readiness, not certificates

Libar has documented controls and readiness evidence aligned with ISO/IEC 27001:2022, CSA CCM / CAIQ v4.1, OWASP ASVS/WSTG and GDPR-oriented practices. Formal ISO certification, a SOC 2 audit, CSA STAR registration and an independent penetration test are not complete.

Checks that exist today

Non-destructive security smoke tests, control tests, data isolation checks and E2E browser scenarios provide measurable evidence of current readiness. They do not replace a future independent penetration test or formal audit.