Security and privacy
Belliq processes guest names, room numbers and payment status. This page describes how that data is protected.
Signed events from Mews
Every incoming event must carry the correct HMAC-SHA256 signature for the hotel it belongs to. Without a valid signature it is rejected, and in production Belliq will not start without a secret configured.
Each hotel sees only its own data
Isolation is enforced by PostgreSQL Row Level Security on every hotel table. The app connects with its own database role that cannot bypass the rules.
Encryption of access tokens and guest data
Mews tokens and selected guest fields are encrypted with Fernet (AES-128-CBC with HMAC-SHA256) before they are stored.
Sign-in
Passwords are stored with Argon2id. Sign-in is rate-limited against guessing, and a signed-out session cannot be reused.
Text links that expire
The link in the text to the on-call operator is signed, valid for two hours and locked to the first device that opens it. It cannot be used as a normal sign-in.
Privacy
Guest data can be anonymised on request, and every lookup of personal data is written to a log that cannot be changed afterwards.
Failures in external services
Calls to Mews, the AI model and the SMS provider go through circuit breakers. If a service drops out, the case goes to a person instead of sitting unhandled.
Control over automation
A new hotel starts in shadow mode. Replies to guests are checked against fixed rules before they are sent, and anything about safety or complaints always goes to a person.
Status as of September 2026
- No independent security audit or penetration test has been done.
- Belliq is not in production at any hotel yet. Hosting is planned on servers in the EU.
- A data processing agreement is drawn up with each pilot hotel.
Security questions? Write to mrmaxwilliam@gmail.com.