Trust

Trusted with the journey

How we protect the data behind millions of bookings, and the practices we hold ourselves to.

01 · Posture

Security as a habit

Travel data is personal by nature: names, journeys, documents, payments. We treat its protection as an engineering habit rather than a compliance exercise, and we design controls to align with recognised standards including PCI DSS for payment flows and modern data protection law across the regions we serve.

02 · Controls

What protects your data

Encryption

All traffic is encrypted in transit with TLS, and data is encrypted at rest. Payment details flow through tokenised, PCI DSS aligned channels and never touch our application logs.

Access

Least privilege by default. Production access requires hardware backed authentication, is limited to named engineers, and every action is logged and reviewed.

Monitoring

The platform is monitored around the clock across regions, with automated alerting and a published uptime record we are happy to share with partners.

03 · Practice

How we operate

Data residency. We host in certified data centres and can discuss regional hosting requirements for enterprise partners during scoping.

Vendor review. Every subprocessor handling partner data passes a security review before integration and is bound by confidentiality obligations.

Incident response. We maintain a tested response plan with clear severity levels, defined communication timelines to affected partners, and blameless reviews afterward.

Business continuity. Backups are automated, encrypted, and restoration is rehearsed, not assumed.

04 · Disclosure

Found something?

We welcome good faith security research. If you believe you have found a vulnerability in any Okugu Tech system, write to hello@okugu.com with the details and we will respond quickly, keep you informed, and credit you if you wish. Please avoid accessing partner data or disrupting service while testing.