Security

Last updated: 13 August 2026

Passkeys and enforced 2FA

Sign in with Google, Microsoft or a passkey — and workspace owners can enforce two-factor for every seat, not just suggest it.

Workspace isolation

Every workspace's data is isolated at the database layer with row-level security policies — each workspace can only ever read its own records.

Australian data residency

Application data is stored and processed in Sydney, Australia, with encryption in transit (TLS 1.2+) and at rest (AES-256).

Yours to leave with

Full export of your clients and bookings at any time, an open API on Pro, and no lock-in contract. Your data is yours, including on the way out.

Sub-processing is documented on the sub-processor list and in the Data Processing Addendum, including how to request the named infrastructure list.

Vulnerability disclosure

Reporting a vulnerability

Email security@bookaiq.com. This inbox is monitored specifically for security reports — please use it instead of general support so nothing sits in a queue.

Please include:

  • What the issue is and why you believe it is a security problem.
  • The exact steps to reproduce it — URLs, requests, and any account or workspace you used.
  • What an attacker could actually achieve with it.

Our machine-readable contact record is published at /.well-known/security.txt (RFC 9116).

What to expect from us

  • Acknowledgement within 2 business days. A real reply from a person, not an autoresponder.
  • An assessment within 10 business days — whether we consider it a vulnerability, and the severity we have assigned.
  • Progress updates until the issue is resolved, and a note when the fix ships.
  • Credit, if you would like it. Tell us how you want to be named.

We do not currently run a paid bug bounty. We will say so plainly rather than leaving the question open.

Safe harbour

If you make a good-faith effort to follow this policy, we will treat your research as authorised conduct. We will not pursue legal action against you, and if a third party does, we will make it known that your testing complied with this policy.

Good faith means: you stop as soon as you have confirmed a vulnerability, you access only the minimum data needed to demonstrate it, you do not degrade the service for anyone else, and you give us a reasonable chance to fix the issue before disclosing it publicly.

In scope

  • bookaiq.com — the marketing site.
  • app.bookaiq.com — the dashboard, public booking pages, and the API.
  • Customer booking pages served on Bookaiq-hosted custom domains.
  • The Bookaiq iOS and Android applications.

We are most interested in: access to another workspace’s data, authentication or session flaws, privilege escalation between roles, payment-handling defects, and anything that exposes customer personal information.

Out of scope

  • Denial-of-service, volumetric, or brute-force testing against our production systems.
  • Social engineering, phishing, or physical attacks against our staff or customers.
  • Reports generated solely by an automated scanner with no demonstrated impact.
  • Missing hardening headers, cookie flags, or TLS configuration preferences with no demonstrated exploit path.
  • Vulnerabilities in third-party services we depend on — please report those to the vendor directly.

Please do not

  • Access, modify, or delete data belonging to any workspace other than one you own or have been given permission to test. If you access another party’s data by accident, stop and tell us immediately.
  • Exfiltrate or retain any customer data.
  • Publicly disclose the issue before we have had a reasonable opportunity to fix it.

Need a test workspace? Ask us at security@bookaiq.com and we will set one up so you never have to touch real customer data.

Other contacts

Privacy questions and data-rights requests: Privacy Policy. General support: support@bookaiq.com.