Security & Trust
Security you can verify — not just trust.
Ironwood runs the operations and billing of airports that answer to auditors, regulators and their own boards. We publish our security posture up front — so you can assess us before you ever send a questionnaire.
Data hosted & backed up in your own regionIn-region data residency
Your data is hosted — and backed up — within your own country or economic region, with a disaster-recovery standby in the same jurisdiction. We deploy into your region, so your data doesn't cross borders.
Encrypted, end to end
Encrypted in transit (TLS 1.2+) and at rest. Credentials live in a managed key vault and are never stored on the server — a stolen database is useless without keys that aren't on it.
Access you control
Multi-factor authentication, a unique accountable login for every user, and role-based permissions enforced on the server. No shared admin accounts.
Your data is yours alone
Every client is isolated at the database level. One tenant can never see another's data — separation is enforced by the database engine, not just the app.
Backed up — and tested
Nightly encrypted backups are pushed off-site, and we restore them every week to prove they work. A backup you've never restored isn't a backup.
Accountable & compliant
A complete audit trail records who did what, and when. We are aligned with the POPI Act and honour your data-subject rights — access, export and erasure.
One security standard. Every region.
As Ironwood grows across regions, every deployment inherits the same central security baseline. Local teams and local hosting — one standard, set centrally and never lowered.
Want the detail?
Our full Security Handbook covers architecture, disaster recovery, incident response and data governance in depth.