Security at Open Limo.
Operators trust Open Limo with their reservations, their clients and their finances. Protecting that data is a core part of how the platform is built and run. This page summarises the commitments that apply across every Open Limo product; detailed documentation is available to customers on request.
Built In, Not Bolted On.
Hosted on AWS
Open Limo runs on Amazon Web Services in the United States, in an environment built for high availability with redundancy across multiple data centres. We use managed AWS services for databases, storage, networking and key management rather than operating our own hardware.
Encryption everywhere
Customer data is encrypted at rest using keys managed in AWS Key Management Service and encrypted in transit using current TLS. Older, insecure protocol versions are refused. Backups are encrypted and stored in more than one AWS region.
Customer separation
Open Limo is a multi-tenant platform. Every customer’s data is isolated at the database layer, so one company’s reservations, clients, members or financial records are never visible to another. Isolation is enforced by the platform on every request, not left to individual features.
Identity and access
Sign-in is handled by Open Limo’s own identity service using modern standards (OAuth 2.1 with PKCE), with two-factor authentication and passkeys available, breach-screened passwords and automatic lockout on repeated failures. Each customer controls who on their team has access and with which role.
Least-privilege operations
Services run with only the permissions they need, secrets are kept in a managed vault and never in code, and access to production by Open Limo staff requires named, individually authenticated accounts. Administrative and data-access activity is recorded in tamper-evident audit logs.
Monitoring and response
A web application firewall, continuous threat detection and centralised logging protect the platform around the clock. Alerts page an on-call engineer, and every incident is reviewed for its root cause and the change that prevents it from recurring.
Secure development
Infrastructure is defined as code and reviewed before it is applied. Every release passes automated tests, including checks that customer isolation and financial-ledger integrity still hold. Dependencies and container images are scanned for known vulnerabilities on every build, and production deployments are gated on those checks.
Payments
Card payments are processed by Stripe, a PCI DSS Level 1 provider. Card numbers are tokenised at the point of entry and never stored on Open Limo systems.
Continuity, Retention and Privacy.
Backups and continuity
Production databases are backed up continuously with point-in-time recovery and an encrypted copy in a second AWS region, so a data-centre failure does not lose customer data.
Data retention
Operational data is kept for as long as it serves the customer’s account. Transient inputs such as received files and logs are retained for defined periods and deleted automatically. Specific retention periods are documented in our customer agreements and available on request.
Privacy and your data
Customer data is used only to provide the service and is never sold. Requests to access, correct or delete personal data are handled promptly by our team. A data-processing agreement is available on request.
Independent assurance
Our controls are reviewed against the live environment on a regular basis, and a technical security summary is available to customers under NDA. Third-party attestation is in progress and reports will be shared as they become available.
Security Questions and Responsible Disclosure.
For security questionnaires, the technical summary, a data-processing agreement, or a call with an engineer, email info@open.limo. If you believe you have found a vulnerability, use the same address with “Security report” in the subject; we acknowledge reports within one business day and ask that you give us reasonable time to address the issue before public disclosure.