Security & Data
Security in Diafa PMS is an architectural choice. Your data stays on your machine, operations continue through outages, access is scoped by role, and every action is logged.
Security philosophy
Diafa PMS is a desktop application with local data storage. This is a deliberate architecture choice, not a limitation. Your front desk data stays on your machine under your control. Cloud sync handles integrations and backups, but daily operations never depend on it.
This architecture means internet outages, cloud incidents, and network failures do not stop your hotel from operating. Guest data is not stored in a shared multi-tenant cloud database. Your data remains yours in practice as well as in principle.
Your front desk data stays on your machine
The front desk app stores all operational data locally. Guest records, reservations, payments, and reports live on your desktop. Your front desk operates independently from the cloud.
Cloud sync, managed by Diafa PMS
Cloud sync is hosted and managed by Diafa PMS. Encrypted connections between your desktop and our cloud. You don't manage servers or databases. We handle the infrastructure.
Encrypted connections
All communication between the desktop app and cloud uses encrypted connections. SSL certificates auto-renew. No unencrypted data in transit.
Nothing lost during outages
Changes queue locally through network drops, power outages, and restarts. When connectivity returns, sync resumes from where it left off.
Four roles, scoped permissions
Admin (full access), Manager (reports and oversight), Receptionist (front desk operations), Housekeeping (cleaning tasks only). Every action logged in a tamper-resistant audit trail. Device authorization for additional security.
Two copies of your data
Cloud sync acts as continuous backup, your data exists on both the local machine and the cloud. Additional backup schedules managed by Diafa PMS.
GDPR compliance
Guest data export on request. Guest data anonymization. Consent tracking. Configurable data retention policy with auto-anonymization after defined period.
No card data on your machine
Online payments through Diafa Direct are processed through compliant payment gateways. Card numbers never touch your infrastructure.
Security controls in practice
How Diafa PMS enforces data protection and operational boundaries in daily use.
Role-based access control
Four distinct roles, Admin, Manager, Receptionist, Housekeeping, each with scoped permissions. Staff see only what their role requires. No lateral access to unrelated data.
Tamper-resistant audit trail
Every action, reservation changes, payment entries, guest modifications, rate adjustments, is logged with timestamp, user, and device. Audit records cannot be edited or deleted.
Device authorization
Each device running Diafa PMS must be authorized. Unauthorized devices cannot connect to your property data. Lost or stolen devices can be revoked remotely.
Encrypted communication
All data in transit between the desktop app and cloud uses SSL/TLS encryption. Certificates auto-renew. No unencrypted data leaves your machine.
Backup and restore
Cloud sync acts as continuous backup. Your data exists on both the local machine and the cloud. Additional scheduled backups managed by Diafa PMS. Restore to any previous state when needed.
Request a security and deployment review
Walk through the architecture, access controls, data residency, and deployment options for your property.
Request a security and deployment review
Walk through the architecture, access controls, data residency, and deployment options for your property.