Operators trust Sixto with guest data, identity documents, payments and messages, so security is part of how the product is built. This page describes what the product does today. We do not claim formal certifications.
Encryption
Data is encrypted in transit between your browser or integration and Sixto. Integration secrets are kept in a credential vault, not in ordinary settings.
Tenant isolation
Sixto is multi-tenant: each organization's data is separated in the application and every query is scoped to the organization, so one customer cannot read another's data.
Roles and permissions
Access is controlled by roles and fine-grained permissions for team members, per property where needed. API keys are scoped, and a connected AI agent never gets more permission than the person who set it up.
Audit logs
Sensitive actions, whether taken by people, API keys or agents, are recorded in an audit log with who acted, on whose behalf, and what changed.
Credential vault
Credentials for integrations (channel managers, locks, email, payments and others) are kept in a vault with its own access trail. Door codes are masked when text is sent to AI providers.
Support access only with consent
The Sixto team can sign in to a customer account only with that customer's consent. Support sessions are read-only by default, visibly marked in the product and recorded in the audit log.
AI safeguards
Text is redacted before it reaches AI providers, including door codes, labelled secrets and identity document numbers. Guest identity documents are read by AI only with the guest's explicit consent. Customer data is not used to train models.
Backups and availability
Production data is backed up regularly by our hosting infrastructure, and we monitor the service for errors and failures.
Responsible disclosure
If you find a vulnerability in Sixto or on this website, please report it to [email protected] with the details needed to reproduce it. We will acknowledge your report, investigate and keep you informed. Please give us reasonable time to fix the issue before sharing it, do not access other customers' data, and do not disrupt the service. We will not take legal action against good-faith research that follows these rules.
Related pages
Privacy Policy, Data Processing Addendum, Subprocessors. Security questions from customers: [email protected].