Security & Trust
Last updated: 07/30/2026
This page is maintained by Hoskins Travel LLC to answer the questions clients most often ask about how Vencresa handles their information. It describes the controls that are in place today and is updated as the platform changes. It is not a third-party certification or audit.
Encryption in transit (HTTPS everywhere)
Every page of Vencresa — including this one, the advisor workspace, the client portal, and every shareable trip link — is served exclusively over HTTPS with a valid TLS certificate. Plain HTTP requests are automatically redirected to HTTPS, and certificates are renewed automatically before they expire.
You can confirm this yourself: look for the lock icon in your browser’s address bar. A site that shows “Not Secure” or no lock at all is not Vencresa.
Encryption at rest
Database records and uploaded files (passport photos, IDs, documents, headshots) are stored on managed infrastructure that encrypts data at rest. Files uploaded to a contact stay scoped to that contact and are served only through short-lived, signed URLs — never as publicly listable links.
Access control
Each advisor account can only see the contacts, trips, documents, and messages that belong to their own workspace. This is enforced at the database layer with row-level security policies, not just in the user interface, so a misbehaving client or browser extension cannot read another advisor’s data.
Travelers who sign in to the client portal can only see their own trip, documents, and consent preferences. Administrative privileges inside the platform are granted through a separate role table and are limited to the smallest set of people who need them.
Authentication
Sign-in is handled by managed authentication infrastructure with industry-standard password hashing and short-lived session tokens that refresh automatically. Google sign-in is available for advisors who prefer not to manage another password. Password resets are sent only to the address on file.
Secure document transfer & portal uploads
Every passport scan, driver’s license, credit card authorization, and trip document is uploaded through the encrypted client portal — never sent as an email attachment. Each file is stored with encryption at rest and delivered through a signed, time-limited URL that expires automatically. Documents are scoped to the contact they belong to and are never available through publicly listable links.
When AI extracts details from an uploaded document, the extracted fields are presented to the advisor for verification before they are saved to the contact record. The original file remains accessible only through short-lived signed URLs inside the advisor workspace and the client’s own portal view.
No PII over email
Vencresa collects passport numbers, government IDs, payment card authorizations, and other sensitive personal information exclusively through the secure client portal. We do not request, accept, or store these details when they arrive by email, chat, or any other uncontrolled channel.
Email is not a controlled environment: messages can be forwarded, cached on servers, and read by third parties. The portal gives travelers a direct, consent-logged, and audit-trailed path to share their documents with their advisor. Row-level security policies ensure that only the advisor and the traveler can view what was uploaded.
Travel IDs & sensitive documents
See Secure document transfer & portal uploads and No PII over email above for how passport scans, driver’s licenses, Global Entry cards, and similar IDs are handled. In summary: they are uploaded directly to the contact through the encrypted portal, never copied into a shared media library, and viewable only through signed, time-limited links after advisor verification.
Consent & communications
Marketing-channel consent (email, SMS, promotional) is recorded with a timestamp and the source of the consent (intake form, advisor-recorded, or client-submitted), and every change is written to an audit log. Clients can review and update their preferences at any time from the portal or from a personalized consent link.
Payments
Card details are processed by PCI-compliant payment providers (such as Stripe). Vencresa does not store full card numbers, CVV codes, or magnetic-stripe data on its own servers. When a card authorization form is used, the sensitive fields are tokenized and revealed only to authorized advisors through audited reveal events.
Backups & availability
The platform runs on managed cloud infrastructure with automated database backups and point-in-time recovery. Application updates are deployed continuously with the ability to roll back if a problem is detected.
Shared responsibility
Security is a shared effort. Vencresa is responsible for the platform controls described above. Advisors are responsible for choosing strong, unique passwords, keeping their devices up to date, and being thoughtful about who they invite to a workspace. Travelers are responsible for protecting the sign-in details to their own portal account.
Reporting a security concern
If you believe you have found a security issue, please email security@vencresa.com. Please include enough detail for us to reproduce the issue and give us a reasonable opportunity to investigate before disclosing it publicly.