Trust
Data Security
This page is maintained by the OnMyBooks team to answer common security questions about the platform. It describes the controls in place today — it is not a certification or an independent audit.
Last updated: 26 July 2026
Controls in place today
- All traffic between browsers and OnMyBooks runs over encrypted HTTPS connections.
- Data is stored in a managed Postgres database with encryption at rest provided by our hosting platform.
- Row-level access rules run in the database, so a signed-in user can only read their own bookings and profile.
- Prices, deposits and internal staff notes are enforced server-side and cannot be altered by a customer request.
- Privileged database credentials are only used inside server-side code and are never exposed to the browser.
- Sign-in is handled by a managed authentication provider; we never store passwords ourselves.
- Guest manage links use unguessable random tokens and are excluded from search engines.
Shared responsibility
We secure the platform, the hosting and the database access rules. Businesses using OnMyBooks are responsible for who they invite to their account, for keeping their own credentials safe, and for deciding what customer information they collect. Customers are responsible for keeping their private manage link private.
What we do not claim
OnMyBooks is not currently certified under SOC 2, ISO 27001, PCI DSS or HIPAA, and we do not offer business associate agreements. Do not store protected health information in the platform. We do not claim end-to-end encryption or that the service is free of vulnerabilities.
Reporting a vulnerability
If you believe you have found a security issue, please report it through the contact page with the words "security report" in the subject. Please give us reasonable time to fix an issue before disclosing it, and avoid accessing other people's data while testing. We acknowledge reports within three business days.
Incidents
If a security incident affects customer data, we will investigate, contain it, and notify affected account holders by email with what happened and what to do, without undue delay.