Security & Trust
Security you can verify, not just trust.
Ironwood runs the operations and billing of airports that answer to auditors, regulators and their own boards. We publish our security posture up front, so you can assess us before you ever send a questionnaire.
Data hosted & backed up in your own regionIn-region data residency
Your data is hosted (and backed up) within your own country or economic region, with a disaster-recovery standby in the same jurisdiction. We deploy into your region, so your data doesn't cross borders.
Encrypted, end to end
Encrypted in transit (TLS 1.2+) and at rest. Credentials live in a managed key vault and are never stored on the server: a stolen database is useless without keys that aren't on it.
Access you control
Multi-factor authentication, a unique accountable login for every user, and role-based permissions enforced on the server. No shared admin accounts.
Your data is yours alone
Every client is isolated at the database level. One tenant can never see another's data. Separation is enforced by the database engine, not just the app.
Backed up, and tested
Nightly encrypted backups are pushed off-site, and we restore them every week to prove they work. A backup you've never restored isn't a backup.
Accountable & compliant
A complete audit trail records who did what, and when. We are aligned with the POPI Act and honour your data-subject rights: access, export and erasure.
One security standard. Every region.
As Ironwood grows across regions, every deployment inherits the same central security baseline. Local teams and local hosting. One standard, set centrally and never lowered.
Want the detail?
Our full Security Handbook covers architecture, disaster recovery, incident response and data governance in depth.