Skip to main content
Security

Security and data protection

Staying is built and operated by Getia AS, a Norwegian company (org. no. 926 610 198). This page lists the controls that are in the product today and the ones that are not, so you can assess Staying without a sales call.

Last reviewed: October 2026

Infrastructure

  • The application and database run on Railway. Cloudflare provides DNS, CDN and edge protection.
  • All traffic is served over HTTPS with HTTP Strict Transport Security, and pages send a nonce-based Content Security Policy.
  • Every provider that processes data, and where, is listed on the subprocessor page. Several are US companies; transfers are covered by the DPA.

Accounts and access

  • Passwords are hashed with bcrypt. Plain-text passwords are never stored.
  • Staff and travel-agent accounts can enable TOTP two-factor authentication; the TOTP secrets are encrypted at rest with AES-256-GCM.
  • Sign-in, magic-link and booking-lookup endpoints are rate limited, and the limiter fails closed if its store is unavailable.
  • Owner, admin and staff accounts are bound to their own property. Only Staying's internal support role can see across properties. Tenant isolation is covered by an automated test suite.

Payments

Guests pay through Stripe's hosted payment components. Card numbers go straight to Stripe and never reach Staying's servers; Staying stores only Stripe's payment references.

Integrations

  • Inbound PMS webhooks are rejected unless they carry a valid HMAC-SHA256 signature made with the secret you configured; signatures are compared in constant time.
  • iCal export feeds use an unguessable per-property token. Anyone with the URL can read availability, so treat it as a secret.

GDPR and guest privacy

  • Online check-in and the WiFi sign-in page record each guest's marketing consent separately from the booking.
  • Guest data can be exported or deleted on request through Staying's GDPR tools, and those actions are written to an audit log.
  • A Data Processing Agreement is available to every customer.

Not available today

  • Single sign-on (SAML, OIDC) and SCIM provisioning.
  • SOC 2, ISO 27001 or other third-party security certifications.
  • A choice of data-hosting region.
  • Customer-managed encryption keys.

Report a vulnerability

Email andreas@getia.no with the details and steps to reproduce. Please give us a reasonable time to fix the issue before disclosing it. The same contact is published in security.txt.

Frequently asked questions

Does Staying store guests' card numbers?
No. Card payments are entered in Stripe's hosted payment components and processed by Stripe. Staying stores the Stripe payment reference, not card numbers.
Is Staying SOC 2 or ISO 27001 certified?
No. Staying does not hold SOC 2, ISO 27001 or PCI DSS Level 1 certification of its own. Card data is handled by Stripe.
Does Staying support single sign-on (SAML or OIDC)?
No. Staff sign in with email and password, with optional TOTP two-factor authentication, or with an emailed magic link.
Who is the data controller for guest data?
You, the operator, are the controller for your guests' data; Staying (Getia AS) processes it on your behalf under the Data Processing Agreement.