Security and privacy

Belliq processes guest names, room numbers and payment status. This page describes how that data is protected.

Signed events from Mews

Every incoming event must carry the correct HMAC-SHA256 signature for the hotel it belongs to. Without a valid signature it is rejected, and in production Belliq will not start without a secret configured.

Each hotel sees only its own data

Isolation is enforced by PostgreSQL Row Level Security on every hotel table. The app connects with its own database role that cannot bypass the rules.

Encryption of access tokens and guest data

Mews tokens and selected guest fields are encrypted with Fernet (AES-128-CBC with HMAC-SHA256) before they are stored.

Sign-in

Passwords are stored with Argon2id. Sign-in is rate-limited against guessing, and a signed-out session cannot be reused.

Text links that expire

The link in the text to the on-call operator is signed, valid for two hours and locked to the first device that opens it. It cannot be used as a normal sign-in.

Privacy

Guest data can be anonymised on request, and every lookup of personal data is written to a log that cannot be changed afterwards.

Failures in external services

Calls to Mews, the AI model and the SMS provider go through circuit breakers. If a service drops out, the case goes to a person instead of sitting unhandled.

Control over automation

A new hotel starts in shadow mode. Replies to guests are checked against fixed rules before they are sent, and anything about safety or complaints always goes to a person.

Status as of September 2026

  • No independent security audit or penetration test has been done.
  • Belliq is not in production at any hotel yet. Hosting is planned on servers in the EU.
  • A data processing agreement is drawn up with each pilot hotel.

Security questions? Write to mrmaxwilliam@gmail.com.