Data Protection & Security
Security Audit: September 2026 · SOC2 / GDPR Compliant
How we safeguard your studio schedules, payment payouts, and client records with passwordless cryptography, multi-tenant database isolation, and global edge encryption.
1. Encryption & Cloud Infrastructure
AirBook runs on modern, fault-tolerant cloud architecture engineered for enterprise reliability and zero single-point-of-failure vulnerability:
All databases, backups, uploaded brand assets, and client profiles are encrypted with industry-standard AES-256 bit keys.
Every request between client booking phones, studio workstations, and our servers is secured over modern TLS 1.3 with Perfect Forward Secrecy.
Databases are continuously replicated with hourly point-in-time recovery points to ensure zero data loss in disaster scenarios.
Traffic is routed through high-speed edge nodes with automated Web Application Firewall (WAF) and layer-7 DDoS mitigation.
2. Passwordless WebAuthn & Biometric Identity
Passwords are fundamentally flawed. They get reused, phished, intercepted, and leaked. AirBook is built 100% passwordless from the ground up using the official FIDO Alliance WebAuthn standard:
How Passkey Authentication Protects You:
- Private Key Remains on Device: Your biometric credential (Face ID, Touch ID, Windows Hello) generates a public-private keypair. The private key never leaves your physical device.
- Immune to Phishing: Passkeys are cryptographically bound to
getairbook.com. Fake phishing websites cannot solicit or intercept your login credentials. - Zero Database Targets: Because our database holds only public validation keys, there are zero passwords for hackers to compromise or breach.
3. Financial Isolation & PCI-DSS Level 1 Compliance
AirBook never touches, routes, or stores raw credit card numbers, CVVs, or cardholder magnetic tracks.
All payment collection, card vaulting for no-show deposit guarantees, and instant merchant bank payouts are delegated directly to Stripe via client-side Stripe Elements and Stripe Financial Services, certified under the most stringent PCI-DSS Level 1 audit standards.
4. Sub-processors & Infrastructure Partners
We work exclusively with vetted, enterprise cloud providers that maintain verified SOC2 Type II, ISO 27001, and GDPR certifications:
5. Security Vulnerability Reporting
We welcome responsible security research. If you discover a potential vulnerability, please notify us immediately:
AirBook Security Team
PGP Encrypted / Direct Contact: security@getairbook.com
Security reports are prioritized with triage within 6 hours.