Security & Trust

Security you can verify, not just trust.

Ironwood runs the operations and billing of airports that answer to auditors, regulators and their own boards. We publish our security posture up front, so you can assess us before you ever send a questionnaire.

Data hosted & backed up in your own region

In-region data residency

Your data is hosted (and backed up) within your own country or economic region, with a disaster-recovery standby in the same jurisdiction. We deploy into your region, so your data doesn't cross borders.

Encrypted, end to end

Encrypted in transit (TLS 1.2+) and at rest. Credentials live in a managed key vault and are never stored on the server: a stolen database is useless without keys that aren't on it.

Access you control

Multi-factor authentication, a unique accountable login for every user, and role-based permissions enforced on the server. No shared admin accounts.

Your data is yours alone

Every client is isolated at the database level. One tenant can never see another's data. Separation is enforced by the database engine, not just the app.

Backed up, and tested

Nightly encrypted backups are pushed off-site, and we restore them every week to prove they work. A backup you've never restored isn't a backup.

Accountable & compliant

A complete audit trail records who did what, and when. We are aligned with the POPI Act and honour your data-subject rights: access, export and erasure.

One security standard. Every region.

As Ironwood grows across regions, every deployment inherits the same central security baseline. Local teams and local hosting. One standard, set centrally and never lowered.

Want the detail?

Our full Security Handbook covers architecture, disaster recovery, incident response and data governance in depth.

Request the Security Handbook