Your guests' data is safe.
Strong encryption, two-factor authentication, CSRF protection and full GDPR compliance. Every identity document is protected from the moment it is scanned and completely deleted after being submitted to Alloggiati Web.
Every layer is protected.
We trust no component by default. Every access is verified, every piece of data is encrypted, and every operation is recorded.
Strong document encryption
Images of identity documents captured during check-in are automatically deleted when the verification and submission process is complete. Only the data required to manage the stay and meet legal obligations is retained in the database. Data is protected with AES-256 encryption, is not publicly accessible, and is never sent to the operator's browser except for information strictly necessary to verify and manage the application.
MFA authentication
Two-factor authentication using a one-time password sent by email is mandatory for any access from an unrecognized device. An active layer of security even if a password is compromised.
CSRF protection and input validation
Every API endpoint is protected against CSRF attacks and rigorously validates all input. Non-compliant data is rejected before reaching the database.
Sensitive credentials never exposed
Questura portal credentials (WSKEY), SMTP keys and payment APIs are encrypted on the server and never pass to the browser. Even an administrator cannot see them in plain text.
Complete JSON export
Download the entire database in JSON format at any time. Your data is yours: moving it to another system, archiving it offline or importing it into accounting software takes one click.
Dedicated VPS for the Structure plan
The Structure plan includes installation on your own server (VPS or on-premise). Data physically hosted in your infrastructure, backups configurable on your storage, and full digital sovereignty.
Regulatory compliance
Designed for GDPR from the start.
Personal data protection is not an add-on — it is part of the architecture. Every technical choice has been evaluated from a GDPR perspective, from document collection to automatic deletion after the mandatory retention period.
Questions about data security?
Our technical team is happy to answer any questions about encryption, GDPR compliance or installation on your own VPS.
