Security & Trust

Security you can verify — not just trust.

Ironwood runs the operations and billing of airports that answer to auditors, regulators and their own boards. We publish our security posture up front — so you can assess us before you ever send a questionnaire.

Data hosted & backed up in your own region

In-region data residency

Your data is hosted — and backed up — within your own country or economic region, with a disaster-recovery standby in the same jurisdiction. We deploy into your region, so your data doesn't cross borders.

Encrypted, end to end

Encrypted in transit (TLS 1.2+) and at rest. Credentials live in a managed key vault and are never stored on the server — a stolen database is useless without keys that aren't on it.

Access you control

Multi-factor authentication, a unique accountable login for every user, and role-based permissions enforced on the server. No shared admin accounts.

Your data is yours alone

Every client is isolated at the database level. One tenant can never see another's data — separation is enforced by the database engine, not just the app.

Backed up — and tested

Nightly encrypted backups are pushed off-site, and we restore them every week to prove they work. A backup you've never restored isn't a backup.

Accountable & compliant

A complete audit trail records who did what, and when. We are aligned with the POPI Act and honour your data-subject rights — access, export and erasure.

One security standard. Every region.

As Ironwood grows across regions, every deployment inherits the same central security baseline. Local teams and local hosting — one standard, set centrally and never lowered.

Want the detail?

Our full Security Handbook covers architecture, disaster recovery, incident response and data governance in depth.

Request the Security Handbook