99.97%
Platform uptime
24/7 monitoring

Security-first guest WiFi

Guest WiFi your security team can stand behind.

Tenant isolationHardened authRate limitingSOC 2
Failed login lockout

Accounts lock after 5 failed attempts with a 15-minute window.

10s
Outbound timeout
Integration requestsblocked
Private IPsrejected
CSP
Content Security Policy

Nonces for inline scripts/styles, plus strict transport and framing headers.

Trust signals

SOC 2 Type II
Certified
GDPR & CCPA
Compliant
99.97% uptime
SLA
24/7 monitoring
Active
Protected assets
Tenant dataGuest PIIRADIUS secretsCRM credentials
Protections

Ten controls. One hardened platform.

Tenant isolation
Brute-force protection
CSRF tokens
CSP & HSTS
Rate limiting
SSRF protection
Input sanitization
Secure cookies
Container hardening
Secret validation
Security architecture

Six defense layers. Built in from day one.

Footfall treats guest data, tenant boundaries, and infrastructure as critical assets. Security isn't a checklist — it's the foundation of the platform.

01

Tenant Isolation

Every dashboard query is scoped to the user's business_id. One tenant cannot access another's locations, customers, campaigns, or analytics.

Strict data boundaries by design.

02

hardened Auth

bcrypt password hashing, account lockout after failed attempts, HttpOnly/Secure/SameSite cookies, and a required SECRET_KEY at boot.

Lockout after 5 failed attempts.

03

Input & Output Safety

CSRF tokens on all forms, sandboxed campaign templates, validated redirects, escaped search terms, and normalized custom CSS.

XSS, SSTI, and open-redirect protected.

04

Rate Limiting & Headers

Flask-Limiter with per-route limits, plus CSP, HSTS, X-Frame-Options, and a strict Permissions-Policy out of the box.

Abuse prevention by default.

05

Integration Security

Webhook and CRM URLs are validated to reject private IP ranges. Outbound requests time out after 10 seconds with SSRF protection.

Public endpoints only.

06

Infrastructure Hardening

Pinned FreeRADIUS image, Redis password requirement, no weak production fallbacks, and RADIUS secrets enforced at container start.

Defense in depth.

100%

Tenant-scoped queries

business_id isolation

Weak production fallbacks

explicit env required

0

Private IP integrations

SSRF protected

24/7

Security monitoring

with incident response

Deep dive

Every security control, documented. Read the feature breakdown.

From bcrypt hashing to container hardening, see exactly how Footfall protects your guests, your tenants, and your infrastructure.

WiFi security isn't optional. It's the cost of admission.

Get a security walkthrough from our team. We'll show you the controls, the architecture, and the compliance posture that make Footfall enterprise-ready.

SOC 2 Type II certified · GDPR & CCPA compliant · 99.97% uptime SLA · security@app.footfall.cloud