Preview build. Prices, contact details and legal text are drafts until Innix confirms them.
Security

How Innix protects guest data and your money

Innix holds your guests’ details and records every naira your property takes. This page says exactly how that is protected, in plain words.

Each property sees only its own data

  • Every record carries its property, and the database itself refuses any read or write across properties. It does not rely on the app remembering to filter.
  • Which property you belong to is decided on our servers from your sign-in, never by the device.
  • Automated tests try to read and change other properties’ data on every endpoint. If one succeeds, the release is blocked.

Your money never passes through Innix

  • Payments settle straight into the property’s own bank account through Paystack. Innix never holds customer funds.
  • Card details are typed into Paystack’s page, not ours. Innix never sees, stores or sends card numbers.
  • Changing the bank account that receives payments needs the owner, a second sign-in step and a notice to the previous contact. It is the most valuable thing a fraudster could change, so it is the hardest.

Encrypted everywhere

  • All traffic uses TLS 1.2 or newer, with no unencrypted fallback.
  • The database, file storage and backups are encrypted with managed keys.
  • Guest ID photos get a further layer of encryption, open only through links that expire in minutes, and are deleted 90 days after departure by default.

Where your data lives

  • On Amazon Web Services in its Cape Town region, in Africa.
  • Backups run daily, are kept for 30 days in a second region, and a restore is tested every month.
  • Production data is never copied into test systems.

Sign-in and staff access

  • Owners must use two-step sign-in.
  • Staff PINs authorise actions during a shift only. They are rate-limited and lock after repeated wrong tries.
  • Removing a staff member or changing their role ends their sessions at once.
  • Permissions are checked on our servers for every request. Hiding a button is not treated as security.

Shared front desk devices

  • Front desk tablets sit in public areas, so we treat them as untrusted.
  • They keep only what the shift needs, encrypted, and never ID photos or full guest histories.
  • A lost device can be switched off centrally. Its stored data is wiped the next time it connects.
  • Work saved while offline is sealed, so a tampered device cannot post fake payments when it reconnects.

A record of every change

  • Every change to a booking, bill, payment or setting is written to a record that cannot be edited or deleted from the app.
  • Actions that need a manager’s PIN record who did it, who approved it, the reason and the money involved.

When Innix staff need to look

  • Support can only view your property read-only, with a written reason, for a limited time.
  • You are notified every time, and every visit is logged.

Testing and fixes

  • An independent penetration test is completed before the first property handles live guest data, and every year after. Serious findings are fixed before launch.
  • Every build is scanned for vulnerable dependencies. Critical fixes ship within 48 hours, high-severity ones within 7 days.

If something goes wrong

  • We keep a written incident response plan and rehearse it.
  • If personal data is breached, we tell affected customers and the regulator within 72 hours of becoming aware.
Sub-processors

Who else handles your data

These companies process data for Innix. We tell customers before we add a new one.

CompanyWhat for
Amazon Web ServicesHosting, database, storage and backups, in the Cape Town region
PaystackPayment links, card payments and settlement to your bank
Meta (WhatsApp Business)Receipts, payment links and daily reports
TermiiSMS when WhatsApp cannot deliver
SentryError monitoring, with personal data removed

Certifications

Innix is not yet certified to SOC 2 or ISO 27001. The controls on this page are built to produce the evidence those audits need, so certification can follow without rebuilding anything.

Found a problem?

If you think you have found a security issue, email security@innix.africa. We reply to every report and will not take action against anyone reporting in good faith.

Ask us anything about how your data is handled

Bring your questions to a demo, or send them by email. We would rather answer them before you sign than after.