Security & Data

Security in Diafa PMS is an architectural choice. Your data stays on your machine, operations continue through outages, access is scoped by role, and every action is logged.

Security philosophy

Diafa PMS is a desktop application with local data storage. This is a deliberate architecture choice, not a limitation. Your front desk data stays on your machine under your control. Cloud sync handles integrations and backups, but daily operations never depend on it.

This architecture means internet outages, cloud incidents, and network failures do not stop your hotel from operating. Guest data is not stored in a shared multi-tenant cloud database. Your data remains yours in practice as well as in principle.

Your front desk data stays on your machine

The front desk app stores all operational data locally. Guest records, reservations, payments, and reports live on your desktop. Your front desk operates independently from the cloud.

Cloud sync, managed by Diafa PMS

Cloud sync is hosted and managed by Diafa PMS. Encrypted connections between your desktop and our cloud. You don't manage servers or databases. We handle the infrastructure.

Encrypted connections

All communication between the desktop app and cloud uses encrypted connections. SSL certificates auto-renew. No unencrypted data in transit.

Nothing lost during outages

Changes queue locally through network drops, power outages, and restarts. When connectivity returns, sync resumes from where it left off.

Four roles, scoped permissions

Admin (full access), Manager (reports and oversight), Receptionist (front desk operations), Housekeeping (cleaning tasks only). Every action logged in a tamper-resistant audit trail. Device authorization for additional security.

Two copies of your data

Cloud sync acts as continuous backup, your data exists on both the local machine and the cloud. Additional backup schedules managed by Diafa PMS.

GDPR compliance

Guest data export on request. Guest data anonymization. Consent tracking. Configurable data retention policy with auto-anonymization after defined period.

No card data on your machine

Online payments through Diafa Direct are processed through compliant payment gateways. Card numbers never touch your infrastructure.

Security controls in practice

How Diafa PMS enforces data protection and operational boundaries in daily use.

Role-based access control

Four distinct roles, Admin, Manager, Receptionist, Housekeeping, each with scoped permissions. Staff see only what their role requires. No lateral access to unrelated data.

Tamper-resistant audit trail

Every action, reservation changes, payment entries, guest modifications, rate adjustments, is logged with timestamp, user, and device. Audit records cannot be edited or deleted.

Device authorization

Each device running Diafa PMS must be authorized. Unauthorized devices cannot connect to your property data. Lost or stolen devices can be revoked remotely.

Encrypted communication

All data in transit between the desktop app and cloud uses SSL/TLS encryption. Certificates auto-renew. No unencrypted data leaves your machine.

Backup and restore

Cloud sync acts as continuous backup. Your data exists on both the local machine and the cloud. Additional scheduled backups managed by Diafa PMS. Restore to any previous state when needed.

Request a security and deployment review

Walk through the architecture, access controls, data residency, and deployment options for your property.

Request a security and deployment review

Walk through the architecture, access controls, data residency, and deployment options for your property.