Servio is built with strong, practical security foundations during beta. We use industry-standard encryption, secure authentication, and Stripe for payment processing.
We've built Servio with security at its core, implementing industry best practices and standards.
Card payments are processed by Stripe, which is PCI DSS compliant. Servio does not store full card details.
We design our data handling around GDPR principles (minimisation, access control, transparency) as a core requirement.
We're targeting high availability as we scale. Reliability is monitored and improved continuously during beta.
Regular dependency checks and security scanning in CI/CD to catch issues early as we ship.
All data in transit uses TLS. Sensitive data at rest is encrypted where applicable, following best practices.
We use secure authentication patterns and session handling to protect accounts and staff access.
Data access is scoped so venues and staff only see what they're permitted to see (role-based and tenant-scoped access).
Payments are processed through Stripe. This reduces your risk footprint and keeps card handling within Stripe's secure environment.
We run regular automated checks to reduce common vulnerabilities and keep dependencies up to date during beta.
Servio is pre-launch. We do not currently claim independent third-party audits/penetration testing, a formal uptime SLA, or standalone PCI certification for Servio itself.
If your venue requires formal assurances, contact us and we'll share what we can today and what's planned next.
We're transparent about our security practices. Reach out to our team to discuss your specific requirements.