GuestlinePortal
Issue 001 · Dublin · August 2026
§ Security whitepaper

Security whitepaper

Version 3.2 · September 2026 · Aligned with ISO/IEC 27001:2022 · Reviewed quarterly

· I ·Scope

This whitepaper describes the technical and organisational security controls in place for the GuestlinePortal service — the Client Portal, the module APIs, the Rezlynx integration surfaces, the Bank of Ireland and AIB payment rails, the OTA connectors and the supporting infrastructure. It is written for Irish hoteliers, their IT teams, group information security officers and third-party auditors.

· II ·Data residency

All personal and financial data is stored in the European Union — primary region EU-Central-1 with a Dublin failover. No data is transferred to any third country. The support ticketing system, the mail relay (mail.guestlineportal.com), the analytics pipeline and the backup vaults all run from EU data centres operated by providers with an EU headquarters. No US CLOUD Act exposure.

· III ·Encryption

All data at rest is encrypted with AES-256. All data in transit is encrypted with TLS 1.3 with modern cipher suites (TLS_AES_256_GCM_SHA384 or TLS_CHACHA20_POLY1305_SHA256). HSTS is enforced with a two-year max-age. Certificate transparency logging is enabled. Backup vaults are encrypted with a separate key hierarchy under HashiCorp Vault.

· IV ·Access control

Production access is restricted to a named set of ten engineers on the Dublin team. Every access requires hardware key MFA (YubiKey or equivalent FIDO2 token) plus a step-up SSO session that expires every four hours. Access is logged and reviewed weekly. Production database queries are proxied through a bastion with query auditing.

· V ·Application security

All code changes require peer review and pass through an automated SAST pipeline before merge. Dependency vulnerabilities are scanned continuously and patched within 24 hours for critical severity, 72 hours for high. Runtime protection at the API edge blocks common OWASP Top 10 attack patterns. Rate limiting is applied per client token to protect the Rezlynx API from downstream traffic surges.

· VI ·Payment security

The Bank of Ireland and AIB payment connector routes all card authorisations through the respective acquirer's PSD2 Strong Customer Authentication and 3-D Secure 2.2 flows. Card data is tokenised at the acquirer; only tokens are stored in the GuestlinePortal environment. Full card numbers never touch our systems. PCI DSS Level 1 compliance is inherited from the acquirer's environment for the tokenised flow.

· VII ·Penetration testing

An EU-based CREST-certified firm performs a full-scope grey-box penetration test annually plus a targeted retest quarterly. The most recent full-scope test was completed in May 2026 and returned no high or critical findings. The report is available under NDA on request.

· VIII ·Business continuity

RPO 15 minutes, RTO 60 minutes for the Client Portal and the module APIs. Backups run every 15 minutes with a 30-day retention. Backup restoration is tested monthly. Disaster recovery from the Dublin failover region has been tested end-to-end twice per year since 2024.

· IX ·Vendor management

Every sub-processor is evaluated against a written questionnaire covering data residency, security controls, sub-sub-processor use and incident response. The current list of authorised sub-processors is maintained in the DPA at /dpa. Any addition is notified to Customers 30 days in advance.

· X ·Regulator

Registered with the Data Protection Commission (DPC) under registration IE-14872. Personal data breach notifications go to the DPC within 72 hours where the Article 33 GDPR threshold is met. The Data Protection Officer is contactable at dpo@guestlineportal.com.