This page explains the controls Itiner currently uses, what agencies remain responsible for, and where to report a security concern. It is not a certification or a promise that risk can be eliminated.
Last reviewed: 5 October 2026
Current controls
What is in place today
Account authentication
Agency accounts use managed authentication and verified user sessions. Password handling is delegated to the authentication provider rather than stored by Itiner application code.
Agency data separation
Database row-level access policies scope protected records to the relevant agency and authenticated user permissions.
Workspace roles
Role checks restrict sensitive team and workspace actions. Agencies should remove accounts that no longer require access.
Client portal links
Published client portals use trip-specific tokenized links. Anyone who receives a valid portal link may be able to view that itinerary, so agencies should treat it as client information.
Encrypted transport
The production site redirects to HTTPS so data is encrypted while traveling between a current browser and the service.
AI assistant connections
ChatGPT, Claude and other AI apps connect through OAuth sign-in with the user's own Itiner account and the same agency data separation. They cannot delete trips or read billing, prices, uploaded documents, or client contact details, and each connection can be revoked in Settings → AI assistants.
Encrypted credentials
GDS connection credentials that agencies save are encrypted with AES-256-GCM before they are stored, and are never shown back in the app.
Daily encrypted backups
The database and uploaded files are backed up every day to a private, encrypted Amazon S3 bucket, using short-lived credentials rather than stored keys. Backups are kept for 30 days and then deleted. This is a daily backup, not continuous point-in-time recovery.
Sign-in and abuse protection
Cloudflare Turnstile protects sign-up, sign-in, password reset and invite forms, and the AI assistant connection is rate limited.
Safer outbound requests
When Itiner fetches a link an agency supplies, such as an external calendar feed, it checks the address first so requests cannot be pointed at internal systems.
Public policies
Privacy, terms, cookie, and data processing pages describe the current contractual and data-handling commitments.
Shared responsibility
What agencies should do
Invite only the team members who need workspace access.
Remove former staff and review roles when responsibilities change.
Share client portal links only with intended recipients.
Avoid adding passport, payment card, medical, or other highly sensitive data unless it is necessary and appropriate.
Verify itinerary details before publishing; security controls do not make generated travel advice accurate.
Scope and limitations
Current scope and limitations
Itiner does not currently claim SOC 2 or ISO 27001 certification.
Client portals are link-accessible experiences, not client account vaults.
No software service can guarantee absolute security or uninterrupted availability.
Detailed contractual terms are governed by the published privacy policy, terms, and DPA.
Report a concern
Contact Itiner support
Email [email protected] with the affected URL or account, what you observed, when it occurred, and a safe way to reproduce it. Do not include passwords, access tokens, or unnecessary client data.