Security

Built so that a mistake is small and a record is kept.

Agencies run their businesses through these products, with their own GDS accounts and their customers' passports behind them. Here is how we protect that, and how to tell us if you find a hole.

Security: how a Sabre login and a passport are protectedOverview
AI-narrated overview of this pageYouTube ↗
Practices

What we do to protect a Sabre login and a customer's passport number.

  • Isolation first

    Your domain identifies your agency before anything else is looked up. Agencies cannot reach each other's data through any screen, address or API, and sub-agencies see only their own downline.

  • Credentials protected

    GDS, airline and aggregator credentials are encrypted at rest and shown back only as masked summaries. Passwords are stored as salted one-way hashes; sign-in providers give us name and email only.

  • Sessions that end

    Signed-in sessions expire after 12 hours, guest sessions after 24. Sensitive actions can require a fresh one-time code, and Buraq B2B contracts can enforce two-factor sign-in: a correct password is followed by a six-digit code to WhatsApp and email. Codes are stored hashed, last five minutes and allow five attempts; a password reset signs every session out.

  • Verified messages

    Inbound webhooks from messaging providers are checked by signature and rejected when they fail. Email senders are authenticated; failures go to a person, never to the assistant.

  • Gates on money

    Booking and live ticketing are off until an agency enables them. Over email, ticketing, payment and cancellation never happen automatically. Wallet debits, holds, voids, refunds and transfers follow the same permission checks in the portal, the console, the assistant and the terminal; a contract can require a one-time code on ticketing and cancellation, and a refund after the void window needs the tenant's approval.

  • Least privilege

    Six roles with scoped permissions; platform-only actions (plans, domains, attribution) cannot be performed by agency admins. Production access is limited to people who operate the service.

  • Everything audited

    System audit, chat audit, booking timeline, activity log and ledger, attributable to a person or an action, readable by agency admins.

  • Environments apart

    Staging and production have separate databases, secrets and domains. Nothing is promoted without the staging checklist; a recovery point is taken before every production change.

  • Keys rotated

    Platform secrets and provider keys are rotated on a schedule and immediately after any suspicion of exposure.

This website

This website follows the same rules.

Few third partiesNo advertising and no external fonts. A strict content-security policy allows only this site, the live demo frame, YouTube's privacy-enhanced player once you press play, and Google Analytics (asked first in the EEA, UK and Switzerland; off at any time from Analytics settings).
HeadersFrames from other sites are refused, content types are not sniffed, referrers are not sent, and camera, microphone and location are disabled for the page itself (the demo frame asks for the microphone only when you use voice).
Responsible disclosure

If you find a weakness, tell us before you tell anyone else.

Write to security@jetnova-ai.com with what you found, where, and how to reproduce it. Our security.txt carries the same address. We acknowledge within two working days, keep you informed, fix confirmed issues in priority order, and credit you if you want it. We do not pursue researchers who follow these rules.

The rules

  • Test only accounts and agencies you own or that we set up for you; never touch another agency's data or a real customer's booking.
  • No denial of service, no spam through the WhatsApp or email channels, no social engineering of our team or agencies' staff, no physical attacks.
  • Stop and report as soon as you can show impact; do not exfiltrate more than you need to prove it.
  • Give us a reasonable time to fix before publishing; we will agree a date with you.

In scope

This website, the B2C bot, Buraq B2B portal and console, the email desks and the administrative applications. Out of scope: the suppliers' and providers' own systems, and issues in third-party software already publicly known and awaiting an upstream fix.

Rewards

We do not run a paid bounty programme today. We do say thank you publicly, and we take findings seriously.

Last reviewed 27 September 2026.