Security
Last updated September 30, 2026
Here's how Travel Pilot protects the agencies and travellers who use TravelPilot AI.
Private workspaces
- Every agency's data is kept separate. The database checks on every request that you belong to the workspace you're trying to read.
- Records can't be linked across agencies. For example, a trip can't be attached to another agency's client.
- Every server action checks your membership again, on top of the database rules.
Accounts and access
- You sign in with a confirmed email and password, or with Google.
- Billing and agency-wide dashboards are only open to agency owners.
- Data is encrypted in transit (HTTPS) and at rest by our hosting provider.
Payments
Subscription payments are handled by Paddle, our Merchant of Record. Card details never reach Travel Pilot's systems. Payment notifications are checked for a valid Paddle signature before anything is recorded.
Human approval
TravelPilot never books, cancels, refunds or charges travellers. Emails are only sent after an agent approves them.
Reporting a problem
If you think you've found a security issue, please contact Travel Pilot through travelpilot.agency. We'll investigate promptly.
