1. Our Approach to Security
Travel businesses trust TripVeer with important information about their teams, leads, customers, suppliers, quotations, itineraries, bookings, and documents. We use layered technical and operational safeguards to help protect that information and keep the platform dependable.
No online service can eliminate every risk. Our approach is to reduce risk, limit access, monitor important activity, and respond quickly when an issue is identified.
3. Encryption and Data Protection
Communications between a user’s browser and TripVeer are encrypted in transit using HTTPS/TLS. Data stored within the managed cloud services supporting TripVeer is protected with encryption at rest.
Sensitive service credentials are protected and are not exposed in public application code. Customers should still avoid entering passwords, complete payment-card details, or unnecessary sensitive personal information in notes and uploads.
4. Secure Authentication
TripVeer uses secure authentication to confirm user identity before allowing access to protected areas. Privileged actions are checked on the server, and readable passwords are not stored in TripVeer business records.
Users should choose a strong, unique password, protect the email account connected to TripVeer, and sign out when using a shared device. Suspected account compromise should be reported immediately.
5. Tenant Isolation and Access Control
Customer workspaces are separated by organisation. Role-based access control and server-side authorisation are used to limit information and actions to the appropriate organisation and authorised users.
Administrators can assign roles based on team responsibilities. They should grant only the access each person needs and promptly remove access when a team member changes role or leaves the organisation.
6. Application Security
TripVeer applies safeguards based on the sensitivity of each feature, including:
- authentication and authorisation for protected operations;
- validation of submitted information and supported files;
- limits on selected public or sensitive requests;
- protected handling of service credentials; and
- error handling designed to avoid unnecessary information exposure.
7. Secure Software Development
TripVeer follows recognised secure software development practices. Security considerations are included throughout design, development, testing, release, and maintenance.
The platform is regularly updated to address bugs, vulnerabilities, and reliability improvements. We also review safeguards as TripVeer introduces new features and integrations.
8. Logging and Monitoring
TripVeer records selected sign-in, system, request, error, and activity information. These records help us operate the service, investigate unusual behaviour, troubleshoot problems, prevent misuse, and improve reliability.
Relevant records are access-controlled. Some business activity and history is also available within the product to support operational visibility for customers.
9. Data, AI, and Service Providers
TripVeer uses reputable cloud and service providers to operate the platform. Information is shared with providers only where needed to deliver the relevant service. Customer-enabled integrations may transfer information to services selected by the customer.
Content submitted to AI features may be processed to generate the requested output. Users should upload only what is needed and review generated content before using or sharing it. More detail about data ownership, processing, retention, providers, and individual rights is available in our Privacy Policy.
10. Service Resilience
TripVeer uses managed cloud infrastructure and recovery measures to reduce the impact of service disruption or data incidents. Limited backups may be maintained for disaster recovery.
Customers should export and retain records required for their own legal, financial, or business-continuity needs. Our contractual service terms are available in the Terms & Conditions.
11. Incident Response
If we identify a suspected security incident, we work to assess what happened, contain the issue, protect relevant information, correct the cause, and restore normal service.
We communicate with affected customers when appropriate and provide notifications required by applicable law. Customers may be asked to reset credentials or disconnect an affected integration as part of the response.
12. Customer Security Best Practices
Customers can strengthen the security of their TripVeer workspace by:
- using a strong and unique password for every account;
- limiting administrator access and reviewing permissions regularly;
- removing former employees and unused accounts promptly;
- keeping browsers, devices, and security software updated;
- checking unexpected requests to export data or change payment details;
- reviewing public quotation and document links before sharing them;
- protecting downloaded files after they leave TripVeer; and
- reporting suspicious activity without delay.
13. Continuous Improvement
Security needs change as technology and threats evolve. TripVeer continues to improve its security capabilities and may introduce additional protections over time, such as multi-factor authentication, additional monitoring, improved access controls, and enhanced auditing. These examples describe potential future improvements and do not represent currently available features unless confirmed in the product or by TripVeer.
14. Responsible Disclosure
We encourage security researchers and customers to report suspected vulnerabilities responsibly. Good-faith reports help us improve TripVeer and are appreciated.
Please send a clear description and safe reproduction steps to info@tripveer.com. Do not access customer data, disrupt the service, perform destructive testing, or publicly disclose an unresolved issue. Please also avoid including passwords or unnecessary personal information in a report.
15. Contact Information
For security questions or to report suspicious account activity, email info@tripveer.com or use our contact page.
TripVeerBrookfield, Bengaluru, Karnataka, India
