Trust

Security at MotelEasy

How we protect your property and guest data · Last updated: September 18, 2026

In short: everything is encrypted in transit, card numbers never touch our servers, passwords and staff login codes are never stored in readable form, the database can't be reached from the internet, and we back it up every night. Found a problem? Email hello@basicoffice.co.uk.

Encryption in Transit

The website, the app and our API are served only over HTTPS (TLS). The app and API also send security headers that tell browsers to always use HTTPS and block common attacks such as clickjacking and content-type sniffing.

Passwords and Staff Login Codes

Account passwords are never stored in plain text — we keep only a salted scrypt hash.

Staff sign in with a 6-digit code. Codes are generated with a cryptographically secure random generator and stored only as a keyed hash (HMAC-SHA256). A code is shown once, when it's created or regenerated — after that, nobody can view it, including us, so managers issue a new one if it's lost.

Repeated failed sign-in attempts are rate-limited to slow down guessing.

Payments

Payments are handled by Stripe, a PCI DSS Level 1 certified payment provider. Card details are entered into Stripe's secure payment form and go straight to Stripe — card numbers never reach or get stored on MotelEasy's servers.

Access to Your Data

Every request is checked against the properties the signed-in user is allowed to access, so staff only see the properties they're assigned to and one customer can't see another's data.

Only authorised personnel can access production systems.

Infrastructure

  • A firewall blocks all inbound traffic except web (HTTPS) and administrative SSH access.
  • The database only accepts connections from the application server itself — it isn't reachable from the internet.
  • Server administration uses SSH keys only; password logins are disabled, and repeated failed attempts are blocked automatically.

Backups

The database is backed up automatically every night and backups are kept for 14 days. We've verified that backups restore completely.

Certifications

We want to be straightforward about this: MotelEasy does not currently hold SOC 2 or ISO 27001 certification. Card payments are processed by Stripe, which is certified to PCI DSS Level 1. If your organisation needs a security questionnaire completed, contact us.

Reporting a Security Issue

If you think you've found a security vulnerability, please email hello@basicoffice.co.uk with "Security" in the subject and enough detail for us to reproduce it. We appreciate responsible reports and will reply as quickly as we can.

When investigating, please:

  • only test against your own account, and never access, change or delete other customers' data;
  • don't run denial-of-service, spam or social-engineering tests;
  • give us reasonable time to fix the issue before sharing it publicly.

Contact

Security questions or reports: hello@basicoffice.co.uk

For how we handle personal data, see our Privacy Policy. For the rules of using the Service, see our Terms of Service.

© 2026 MotelEasy. All rights reserved.