Security
How the platform protects your portfolio data.
Last updated 16 September 2026 ยท Questions: info@sharp-stay.co.za
Tenant isolation
Every record belongs to an organization, and database-level row security policies prevent one organization from reading or changing another's data.
Payments
Card data never touches Sharp-Stay servers. Payments are processed by a licensed provider, confirmed through signed webhooks, and reconciled server-side. Payment outcomes are never trusted from the browser.
Access control
Roles limit what each team member can see and do. Sensitive actions are written to an immutable audit log.
Reporting a vulnerability
If you believe you have found a security issue, contact us immediately so we can investigate.
This document is provided for transparency and does not constitute legal advice.