Security

Built around separation, scope, and source control.

The review MVP keeps provider credentials server-side, scopes tenant records by organization, and avoids storing passports or traveler payment cards.

Tenant isolation

Organization identity comes from the authenticated server session. Request bodies and subdomains never decide authorization.

Credential separation

Platform credentials are server-side, redacted from logs, versioned for rotation, and never returned through agency APIs.

Safe outbound links

Deep links require HTTPS, an approved provider host, no embedded credentials, and a fresh policy check before return.

Data boundary

What Tourdesk Search does not collect.

Traveler card dataNot collected
Passport dataNot collected
Supplier portal passwordsNever accepted
Provider secrets in browser codeServer-side only

Report a security concern to security@voyagefoundry.com.

Prices and availability may change until confirmed with the booking provider. Tourdesk Search compares travel options and prepares proposals but does not sell, book, or process payment for travel services.