How we protect your property and guest data.
Sabee is operated as an EU-based platform under GDPR, with data hosted inside the European Union, encrypted at rest and in transit, and covered by an ISO 27001-aligned information security programme.

The baseline every customer gets
- EU data residency (Frankfurt primary, Dublin secondary)
- AES-256 encryption at rest, TLS 1.3 in transit
- Daily encrypted backups with 30-day retention
- Role-based access control with per-property permissions
- Optional single sign-on (SAML) for Enterprise plans
- Two-factor authentication available on every user account
- Full audit log of user actions retained for 12 months
- Signed Data Processing Addendum with every paying customer
Infrastructure
Sabee runs on a multi-availability-zone deployment in Frankfurt with a warm standby in Dublin. Both regions are inside the European Union, and no personal data ever transits infrastructure outside the EU/EEA without an explicit customer approval and a corresponding contractual safeguard.
Every application service is stateless and horizontally scaled behind a load balancer. Databases run in a synchronous primary/replica cluster with automatic failover, and are backed up to encrypted object storage every six hours. Point-in-time restore is available across the previous 30 days.
Encryption
Guest personal data is encrypted at rest with AES-256 GCM. Sensitive fields (payment tokens, government identifier numbers when captured for hotel registration compliance) are additionally encrypted at the application layer with keys managed in a hardware security module. TLS 1.3 is enforced on every public endpoint with a strict transport-security policy and HSTS preload.
Payment data
Sabee never stores raw card numbers. Card capture is delegated to our PSP partners (Stripe, Adyen or a customer-supplied processor), which return tokens Sabee stores in place of the card. This means the Sabee platform is out of PCI DSS scope for card storage — you inherit the PCI Level 1 certification of the PSP you connect.
Access control
Every user in a Sabee tenant is assigned a role with specific permissions. Common roles ship pre-defined (Owner, General Manager, Front Desk, Housekeeping, Revenue Manager, Accountant, Auditor) and can be customised. Multi-property tenants can further restrict roles per property so a regional manager only sees their region and a general manager only sees their property.
Two-factor authentication (TOTP) is available on every account and can be enforced tenant-wide. Enterprise customers can connect their identity provider via SAML for single sign-on, and provision or deprovision users through SCIM.
GDPR & the DPA
Sabee is operated by an EU-based data controller and processor. Every paying customer signs a Data Processing Addendum that meets the requirements of GDPR Article 28, including sub-processor disclosure, breach notification within 72 hours, and cooperation with data subject rights requests. See the full DPA and privacy policy.
Guests can exercise data subject rights (access, rectification, erasure, portability, restriction, objection) either directly through you as the controller, or by writing to our Data Protection Officer at privacy@sabee.esesun.com. We respond within one calendar month per GDPR requirement.
Backups & disaster recovery
Backups are encrypted, stored in a separate region from the primary database, and tested for restore integrity every quarter. The recovery point objective (RPO) is 6 hours in the worst case and 15 minutes typically. The recovery time objective (RTO) is 4 hours for a full region failover, well under 1 hour for individual service failures.
Vulnerability management
Every code change goes through automated static analysis, dependency vulnerability scanning, and peer review before it can be deployed. External penetration testing is performed twice a year by an independent CREST-accredited testing firm, and the summary report is available on request to any prospective or existing customer under NDA.
Sabee operates a responsible disclosure programme at security@sabee.esesun.com — reports are triaged within one working day and eligible findings are rewarded.
Uptime and status
Sabee has delivered 99.98% availability over the trailing twelve months. Real-time platform status, incident history and scheduled maintenance windows are published at status.sabee.esesun.com. Enterprise plans include an SLA with financial remedy for periods below 99.9% monthly availability.
Certifications
Sabee's information security programme is aligned with ISO 27001, and formal certification is on the 2027 roadmap. SOC 2 Type II is under consideration for North American expansion. GDPR compliance is continuously maintained and independently reviewed annually by a certified Data Protection Officer.
Need to send this to your CISO or DPO?
We can share a security whitepaper, the current pen-test summary, and our sub-processor list under NDA — usually within a working day.