Justo

Security

How Justo protects your hotel's data and guest communications

Last updated: April 2026 | ai.justo.ua

At Justo, security is built into every layer of the platform — from how guest messages travel between Instagram and our servers, to how your hotel's knowledge base and access tokens are stored. Below is a clear overview of what we do to keep your data safe.

1. Data Encryption

Layer Protection
Data in transit All communication between your browser, the Justo server, and the Meta Instagram API uses TLS 1.2+ (HTTPS). No data is ever transmitted over unencrypted connections.
Data at rest Sensitive data - including Meta access tokens and message history - is stored server-side with restricted production access and operational safeguards.
Access tokens Instagram Page Access Tokens are stored server-side and never exposed in logs, frontend code, public pages, or API responses. They are used only server-side to send messages via the Meta API.
AI API calls Guest message content sent to the configured LLM API provider is transmitted over encrypted connections. Justo minimizes identifiers in prompts and only sends content needed to generate a hotel response.

2. Access Control

Admin panel access is protected by email + password authentication

Each hotel account is fully isolated — no cross-account data access is possible

Manager roles limit access to only the conversations of their connected hotel

Internal Justo team access to production data is restricted to authorized personnel only, and all access is logged

Meta access tokens are scoped to minimum required permissions: instagram_manage_messages, instagram_basic, pages_show_list, pages_manage_metadata

3. Infrastructure

The Justo platform is hosted on cloud infrastructure in the EU region

Database and application servers are isolated in a private network — not directly accessible from the internet

Webhook endpoints are protected by Meta's signature verification (X-Hub-Signature-256) — all unverified requests are rejected

Backups and operational exports are retained only as needed for recovery and are purged according to the retention policy

Production health, logs, and critical integration endpoints are monitored for operational issues

4. Data Isolation Between Hotels

Justo serves multiple hotel clients through a single Meta application using a multi-tenant architecture. Data isolation is enforced at every level:

Each hotel's data is stored with a unique hotel_id — database queries always filter by this identifier

Instagram webhook events are routed by Page ID, which is mapped to exactly one hotel account

No hotel can access the conversation history, knowledge base, or settings of another hotel

AI agent context is built fresh for each conversation, using only the knowledge base of the specific hotel

5. Meta Platform Security

Justo is a registered Meta developer application with verified business status

All webhook events from Meta are verified using the app secret signature before processing

OAuth tokens are stored server-side and may require re-authorization if Meta expires or revokes the connection

If a hotel disconnects their Instagram account, their access token is deleted within 24 hours and webhook subscriptions are removed

Justo complies with Meta's Platform Terms regarding data handling and security incident reporting

6. AI Agent Security

Guest messages are processed by the AI model to generate responses — they are not stored by the AI provider for training purposes (API usage policy)

The AI agent operates within strict content guidelines defined in the system prompt — it cannot perform actions outside of responding to messages

Human handoff (HUMAN_TAKEOVER state) immediately stops AI processing for that conversation

The AI cannot make financial transactions, access external systems, or perform actions beyond sending a text reply

7. Incident Response

In the event of a security incident affecting hotel or guest data:

Justo will notify affected clients within 72 hours of becoming aware of the incident

Notification will include the nature of the incident, data affected, and steps taken

If the incident involves Meta platform data, Justo will also notify Meta within 24 hours as required by Meta's Platform Terms

Affected access tokens will be immediately revoked and clients will be asked to re-authorize

8. Your Responsibilities

Security is a shared responsibility. Hotel clients are responsible for: keeping admin panel credentials secure, promptly reporting suspicious activity, ensuring only authorized staff have access to the admin panel, and disconnecting the Instagram integration if an employee with access leaves.

Use a strong, unique password for your Justo account

Do not share your login credentials with unauthorized persons

Report any suspected unauthorized access immediately to security@justo.ua

9. Contact

For security concerns or vulnerability reports: security@justo.ua

We take all security reports seriously and will respond within 24 hours.

Justo Security Overview | Version 1.0 | April 2026 | https://ai.justo.ua/security