Tenant and property isolation
Tenant and property boundaries separate guests, reservations, rooms, billing, users and operational records between clients and properties.
Role-based access
Reception, management, administration and the platform have different permissions. MFA, recovery codes and step-up verification provide additional protection for sensitive actions.
Audit and Control of Sessions
Security and audit logs, session review and revocation, CSV exports and network allow/block rules give the team a record and a way to respond.
Data protection and life cycle
HTTPS transmission, controlled backups, secure records and automation for retention or anonymisation form part of the technical foundation. Exact retention periods and production use depend on the contract, legal basis and approved policy.
Evidence of readiness, not certificates
Libar has documented controls and readiness evidence aligned with ISO/IEC 27001:2022, CSA CCM / CAIQ v4.1, OWASP ASVS/WSTG and GDPR-oriented practices. Formal ISO certification, a SOC 2 audit, CSA STAR registration and an independent penetration test are not complete.
Checks that exist today
Non-destructive security smoke tests, control tests, data isolation checks and E2E browser scenarios provide measurable evidence of current readiness. They do not replace a future independent penetration test or formal audit.
