Security
How Justo protects your hotel's data and guest communications
At Justo, security is built into every layer of the platform — from how guest messages travel between Meta messaging channels and our servers, to how your hotel's knowledge base and access tokens are stored. Below is a clear overview of what we do to keep your data safe.
1. Data Encryption
| Layer | Protection |
|---|---|
| Data in transit | All communication between your browser, the Justo server, and Meta Instagram / Facebook Messenger / WhatsApp APIs uses TLS 1.2+ (HTTPS). No data is ever transmitted over unencrypted connections. |
| Data at rest | Sensitive data — including Meta access tokens and message history — is encrypted at rest using AES-256 encryption in the database. |
| Access tokens | Instagram Login, Facebook Page, and WhatsApp setup access tokens are stored encrypted and never exposed in logs, frontend code, or API responses. They are used only server-side to receive and send messages via Meta APIs. |
| AI API calls | Guest message content sent to the LLM provider (Anthropic/OpenAI) is transmitted over encrypted connections. No personally identifiable identifiers are included in API calls. |
2. Access Control
- Admin panel access is protected by email + password authentication
- Each hotel account is fully isolated — no cross-account data access is possible
- Manager roles limit access to only the conversations of their connected hotel
- Internal Justo team access to production data is restricted to authorized personnel only, and all access is logged
- Meta access tokens are scoped to minimum required permissions, such as instagram_business_basic / instagram_business_manage_messages for Instagram, pages_messaging / pages_manage_metadata for Facebook Messenger, and whatsapp_business_management / whatsapp_business_messaging for WhatsApp
3. Infrastructure
- The Justo platform is hosted on cloud infrastructure in the EU region
- Database and application servers are isolated in a private network — not directly accessible from the internet
- Webhook endpoints are protected by Meta's signature verification (X-Hub-Signature-256) — all unverified requests are rejected
- Automatic backups run daily. Backups are encrypted and retained for 30 days
- Server infrastructure is monitored 24/7 with automated alerting for anomalies
4. Data Isolation Between Hotels
Justo serves multiple hotel clients through a single Meta application using a multi-tenant architecture. Data isolation is enforced at every level:
- Each hotel's data is stored with a unique hotel_id — database queries always filter by this identifier
- Instagram webhook events are routed by connected Instagram account ID, and WhatsApp webhook events are routed by phone_number_id; each route is mapped to exactly one hotel account
- No hotel can access the conversation history, knowledge base, or settings of another hotel
- AI agent context is built fresh for each conversation, using only the knowledge base of the specific hotel
5. Meta Platform Security
- Justo is a registered Meta developer application with verified business status
- All webhook events from Meta are verified using the app secret signature before processing
- OAuth tokens are stored encrypted and refreshed before expiry — expiry monitoring runs daily
- If a hotel disconnects their Instagram or WhatsApp connection, the access token is deleted within 24 hours and webhook subscriptions are removed where supported by Meta
- Justo complies with Meta's Platform Terms regarding data handling and security incident reporting
6. AI Agent Security
- Guest messages are processed by the AI model to generate responses — they are not stored by the AI provider for training purposes (API usage policy)
- The AI agent operates within strict content guidelines defined in the system prompt — it cannot perform actions outside of responding to messages
- Human handoff (HUMAN_TAKEOVER state) immediately stops AI processing for that conversation
- The AI cannot make financial transactions, access external systems, or perform actions beyond sending a text reply
7. Incident Response
In the event of a security incident affecting hotel or guest data:
- Justo will notify affected clients within 72 hours of becoming aware of the incident
- Notification will include the nature of the incident, data affected, and steps taken
- If the incident involves Meta platform data, Justo will also notify Meta within 24 hours as required by Meta's Platform Terms
- Affected access tokens will be immediately revoked and clients will be asked to re-authorize
8. Your Responsibilities
- Use a strong, unique password for your Justo account
- Do not share your login credentials with unauthorized persons
- Report any suspected unauthorized access immediately to info@justo.com.ua
9. Contact
For security concerns or vulnerability reports: info@justo.com.ua
We take all security reports seriously and will respond within 24 hours.
Justo Security Overview | Version 1.1 | June 2026 | ai.justo.ua/security