Trust and data protection

How Itiner protects agency and itinerary data

This page explains the controls Itiner currently uses, what agencies remain responsible for, and where to report a security concern. It is not a certification or a promise that risk can be eliminated.

Last reviewed: 14 July 2026

Current controls

Account authentication

Agency accounts use managed authentication and verified user sessions. Password handling is delegated to the authentication provider rather than stored by Itiner application code.

Agency data separation

Database row-level access policies scope protected records to the relevant agency and authenticated user permissions.

Workspace roles

Role checks restrict sensitive team and workspace actions. Agencies should remove accounts that no longer require access.

Client portal links

Published client portals use trip-specific tokenized links. Anyone who receives a valid portal link may be able to view that itinerary, so agencies should treat it as client information.

Encrypted transport

The production site redirects to HTTPS so data is encrypted while traveling between a current browser and the service.

Public policies

Privacy, terms, cookie, and data processing pages describe the current contractual and data-handling commitments.

What agencies should do

  • Invite only the team members who need workspace access.
  • Remove former staff and review roles when responsibilities change.
  • Share client portal links only with intended recipients.
  • Avoid adding passport, payment card, medical, or other highly sensitive data unless it is necessary and appropriate.
  • Verify itinerary details before publishing; security controls do not make generated travel advice accurate.

Current scope and limitations

  • Itiner does not currently claim SOC 2 or ISO 27001 certification.
  • Client portals are link-accessible experiences, not client account vaults.
  • No software service can guarantee absolute security or uninterrupted availability.
  • Detailed contractual terms are governed by the published privacy policy, terms, and DPA.

Report a concern

Contact Itiner support

Email dakshbathla@navitallabs.com with the affected URL or account, what you observed, when it occurred, and a safe way to reproduce it. Do not include passwords, access tokens, or unnecessary client data.

Privacy policyData processing agreementContact