Nasıl kurulduğu, olduğu gibi.How it is built, as it is.
Bu sayfa BT değerlendirmesi içindir. İddia değil, mekanizma anlatır.This page is for the IT evaluation. It describes mechanisms, not claims.
Misafir verisiGuest data
Misafirin e-postası ve telefonu Leonn'da saklanmaz. Gerektiğinde otelin PMS'inden okunur ve kullanıldıktan sonra tutulmaz. Misafir, uygulamaya hesap açarak değil, odadaki QR ve resepsiyonun verdiği altı haneli kodla girer.The guest's e-mail and phone are not stored by Leonn. When needed they are read from the hotel's PMS and not retained afterwards. The guest does not open an account; they enter with the QR in the room and a six-digit code from reception.
Altı haneli kod hiçbir yerde açık metin olarak saklanmaz; yalnızca tek yönlü bir özeti tutulur. Yanlış denemeler kaynağa göre sınırlanır. Erişim, check-out'tan sonra kısa bir süre içinde kendiliğinden sona erer.The six-digit code is never stored in the clear; only a one-way digest is kept. Wrong attempts are rate-limited per source. Access ends by itself shortly after check-out.
Kullanım ölçümü yalnızca toplam sayılarla yapılır. Tek bir misafir izlenmez; bu yüzden sitede çerez banner'ı yoktur.Usage is measured in aggregate counts only. No individual guest is tracked, which is why there is no cookie banner.
Otel bazında izolasyonPer-hotel isolation
Her satır otel kimliği taşır ve veritabanı satır düzeyinde güvenlik kurallarıyla korunur: bir otelin bağlantısı yalnızca kendi satırlarını görebilir. Bu, uygulama kodundaki bir filtre değil, veritabanının kendi kuralıdır; uygulama hatalı olsa bile devrededir. Kurallar 345 senaryoluk otomatik bir test matrisiyle her sürümde doğrulanır.Every row carries a hotel identifier and the database enforces row-level security: a hotel's connection can see only its own rows. This is a rule of the database itself, not a filter in application code, and it holds even if the application is wrong. The rules are verified on every release by an automated matrix of 345 scenarios.
Kurulum seçenekleriDeployment options
- Otelde: uygulama ve veritabanı otelin kendi makinesinde çalışır; dışarıya yalnızca giden bir tünel bağlantısı açılır, gelen port açılmaz. Veritabanı binadan çıkmaz.On-premise: the application and database run on the hotel's own machine; the only external connection is an outbound tunnel, no inbound port is opened. The database never leaves the building.
Tüm trafik HTTPS üzerindendir; alan adı tarayıcıların HSTS ön yükleme listesindedir, yani düz HTTP hiç kabul edilmez.All traffic is HTTPS; the domain is on browsers' HSTS preload list, so plain HTTP is never accepted.
Yedekleme ve geri yüklemeBackup and restore
Veritabanı her gece yedeklenir. Geri yükleme yalnızca yazılı bir prosedür değildir; kurulumdan önce uçtan uca prova edilir. Aktivasyon kodlarının doğrulanması için gereken anahtar, yedekten ayrı tutulur: iki parçadan biri tek başına işe yaramaz.The database is backed up nightly. Restore is not just a written procedure; it is rehearsed end to end before go-live. The key needed to verify activation codes is kept apart from the backup: either half alone is inert.
PMS kesintisindeWhen the PMS is down
PMS'e ulaşılamadığında Leonn çalışmaya devam eder. Resepsiyon konaklamayı elle açabilir; PMS geri geldiğinde kayıtlar uzlaştırılır. Kesinti sırasında PMS kaynaklı girişler, taze olmayan veriye güvenmemek için durdurulur — bu, misafir güvenliği için bilinçli bir tercihtir.When the PMS is unreachable, Leonn keeps working. Reception can open a stay by hand; records are reconciled when the PMS returns. During the outage, PMS-sourced logins are paused rather than trusting stale data — a deliberate choice for guest safety.
Denetim iziAudit trail
Girişler, kod üretimi, oda değişiklikleri ve personel işlemleri yalnızca eklenebilen bir olay kaydına yazılır. Kayıtlar güncellenemez ve silinemez; bu, en yetkili hesaplar için de geçerlidir.Logins, code issuance, room changes and staff actions are written to an append-only event log. Entries cannot be updated or deleted, and that holds for the most privileged accounts too.
SorularQuestions
BT ekibinizin sorularını hello@leonn.app adresine yazın; mimariyi bir görüşmede ayrıntısıyla anlatırız.Send your IT team's questions to hello@leonn.app; we walk through the architecture in a call.