Security and privacy

Designed around least access.

Travel documents are sensitive. Travel Pro separates ownership, trip membership, resource visibility, and delivery recipients so convenience does not silently widen access.

Identity

Passwordless email codes

Short-lived one-time codes, verification checks, throttling, replay prevention, and bot-defense controls.

Invitations

Hashed and expiring

Traveler claim tokens are stored as hashes, expire in seven days, are single use, and require the exact invited email.

Authorization

Role and membership checks

Agent and traveler contexts are distinct. Shared trips do not imply access to every file inside them.

Documents

No authenticated page caching

The service worker avoids portals, documents, app screens, and API requests. Sensitive HTML is never used as an offline fallback.

Email

Safer staging delivery

Staging can redirect every outgoing message to a controlled inbox while preserving intended-recipient records for testing.

Operations

Auditable actions

Claim, document, trip, reminder, subscription, and delivery actions remain traceable for support and incident review.