Beautiful Greek villa interior representing Filoxenos hospitality

Security Overview

Last updated: April 10, 2026

Filoxenos implements technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration and disclosure.

1. Secure transmission

All data transmitted to and from the Filoxenos platform is protected using TLS/HTTPS.

2. Encryption at rest

Personal data stored in the database is protected through encryption at rest. Booking data is stored in encrypted form and is not directly readable in plain text from a database dump.

3. Hosting and infrastructure

Filoxenos uses infrastructure located in Frankfurt, Germany (eu-central-1 / fra1) for application hosting and function execution. Database and backend infrastructure are operated in the EU region (eu-central-1). DNS and nameserver services are provided separately. Cloudflare is currently used only for DNS and nameserver services, without proxy or CDN functionality.

4. Access controls

Access to production systems is restricted to authorised personnel only. Access to production-related data is limited to company management and developers, and only to the extent necessary for operating, maintaining and securing the service. Encrypted booking data is not directly readable in plain text.

5. Multi-factor authentication

Privileged internal accounts used to administer infrastructure and production systems are protected with multi-factor authentication.

6. Backup and recovery

Daily rolling backups are created through Supabase. Backup snapshots are retained for 7 days, allowing restoration from daily snapshots covering the previous 7 days.

7. Monitoring and maintenance

Filoxenos maintains operational and security-related controls to support system reliability, maintenance and the identification of technical issues and potential security events.

8. Incident handling

Security incidents are assessed and handled through internal response procedures. Where required by applicable law, affected customers are informed without undue delay.

9. Ongoing review

Security measures are reviewed and updated as the platform and its infrastructure evolve.