Security

Last updated: July 18, 2026

This page describes Visby’s security practices for the consumer app, marketing site, and hotel partner products. For privacy rights and subprocessors, see the Trust Center.

1. Infrastructure

2. Access control

3. Secrets & integrations

4. Application security

5. Payments

Consumer purchases use Apple / Google In-App Purchase. Hotel payments use Stripe Connect where enabled. Visby does not store full payment card numbers; PCI scope is largely carried by those processors.

6. Incident response

Suspected security incidents are triaged by severity. Where personal data of EU/UK residents is involved, we aim to notify supervisory authorities within 72 hours when required by GDPR, and affected customers without undue delay. Report issues to hello@visbytravel.com with subject “Security”.

7. SOC 2

Our control set is designed to map to SOC 2 Trust Services Criteria (Security). We do not claim SOC 2 certification until an independent auditor issues a report. Enterprise customers may request status updates and, when issued, a report under NDA.

8. Related links