Security

How CockpitMod protects your Dirs21 API credentials and hotel data.

Encryption

All data transmitted between your browser, the CockpitMod Platform and the Dirs21 API is encrypted using TLS 1.2 or TLS 1.3. Dirs21 API keys stored in the CockpitMod platform are encrypted at rest using AES-256. Encryption keys are managed in a dedicated key management service and rotated quarterly.

Access controls

Access to production data is restricted to authorised CockpitMod engineering staff with a legitimate operational need. All production access is logged. Staff members use multi-factor authentication to access production systems. Access rights are reviewed monthly and revoked immediately upon role change or departure.

Infrastructure

The CockpitMod Platform is hosted on infrastructure within the European Economic Area. Servers are isolated in virtual private networks. Database access requires an encrypted tunnel and cannot be accessed from public networks. Automated backups are taken daily and retained for 30 days.

Incident response

We maintain an incident response procedure covering detection, containment, notification and remediation of security incidents. In the event of a personal data breach affecting your data, we will notify you within 72 hours as required by GDPR. Security incidents can be reported to support@cockpitmod.org.

Responsible disclosure

If you discover a security vulnerability in the CockpitMod Platform, please report it responsibly by email to support@cockpitmod.org. Include a description of the vulnerability, steps to reproduce and the potential impact. We will acknowledge receipt within 2 business days and aim to resolve confirmed vulnerabilities within 30 days.

Your Cart

Your cart is empty.