SECURITY
Security built into the operating workflow.
Avrenor Stays uses layered account, application and infrastructure controls to protect customer workspaces without making claims beyond the controls currently in place.
Last updated: September 20, 2026
Account protection
Authentication is handled through secure account workflows. Passwords are not stored in readable form by Avrenor Stays. Email verification, password-reset controls, time-limited invitation or access links and session management help reduce unauthorized access.
Roles and workspace separation
Workspace membership and user roles restrict access to the organization and functions a person is authorized to use. Owners and managers can control team access, while specialized users such as cleaners receive views aligned with their assigned work.
Data transmission and infrastructure
Production traffic is served over HTTPS. Avrenor Stays relies on managed hosting, database, authentication, storage and communication providers and limits service credentials to server-side environments where required. Public sharing features use dedicated tokens rather than exposing an authenticated workspace.
Operational safeguards
- Access checks are applied to protected application routes and data operations.
- Sensitive configuration values are kept outside the public source code.
- Application and delivery logs support troubleshooting and abuse investigation.
- Dependencies, permissions and production changes are reviewed as the service develops.
Customer responsibilities
Customers should use unique passwords, protect email accounts, remove access when team members leave, assign the least access required and avoid placing unnecessary sensitive information in free-text notes or shared links.
Report a security concern
Please send a clear description and affected URL to info@avrenor.com. Do not include passwords, access tokens or unnecessary personal data.