Skip to content

Trust

Security

We take the security of our guests' and partners' data seriously.

Report a vulnerability

If you discover a vulnerability, email concierge@isleofmallorca.com with the subject “Es Fangar security”. We will review the report and coordinate responsible follow-up.

concierge@isleofmallorca.com · /.well-known/security.txt

Technical posture

  • · The public website is served over HTTPS.
  • · Application secrets are managed through environment variables and are not published in source code.
  • · Full payment-card details are handled on external hosted payment pages; Es Fangar does not request or store complete card numbers.
  • · Administrative access requires authentication and role-based permission; administrative actions are written to an audit log.
  • · Selected sensitive public operations are rate-limited to reduce automated abuse.
  • · Requests for data access, correction, export or deletion can be sent to our concierge team.