Security at Book'd Out
Your business runs on its calendar, and your clients trust you with their details. Here is how we look after both.
Protecting your account
Encrypted connections
Every page and every booking is served over HTTPS with TLS. There is no unencrypted access to the platform.
Strong password storage
Passwords are hashed with Argon2id, a modern memory-hard algorithm. We never store or log a password in readable form.
Two-factor authentication
Business accounts can add a second sign-in step using any standard authenticator app, with single-use recovery codes as a backup. Once it is on, a password alone is not enough to get in.
Server-side sessions
Sign-ins are backed by database-stored sessions that expire and can be revoked. Session cookies are HttpOnly, and the database keeps only a hash of each session token.
Role-based access
Owner, manager, and staff roles limit what each team member can see and change. Staff see their schedule, not your billing.
Card details never touch our servers
All card payments run through Stripe, a certified PCI DSS Level 1 provider. Card numbers go straight from your customer to Stripe and are never seen, stored, or processed by us.
Protecting your data
Hosted in Sydney, Australia
The platform runs on Fly.io infrastructure in the Sydney region, and the production database lives on an Australian volume.
Nightly offsite backups
The database is backed up every night to Cloudflare R2 object storage, offsite and encrypted at rest, so a hosting failure does not mean lost bookings.
Straightforward Australian billing
Subscriptions are billed in Australian dollars with GST included. No surprise currency conversions.
Deletion on request
Want your data removed? Email support and we will delete it. Our Privacy Policy sets out exactly what we hold and why.
What we do not claim
We keep this page honest. Book'd Out does not currently hold formal certifications such as ISO 27001 or SOC 2, and we will not pretend otherwise. What you read above is what is actually built and running. Card handling is certified through Stripe, whose PCI DSS Level 1 status covers the entire payment path.
Questions about security, or something to report? Contact us at [email protected]. See also our Privacy Policy and Terms of Service.