Security & Responsible Disclosure

How we protect your data and how to report a vulnerability

Security is fundamental to how Holiday Lydian operates. This page summarises the technical and organisational measures we use to protect the platform and your data, and sets out how security researchers can responsibly report a vulnerability. A machine-readable version is available at /.well-known/security.txt.

Security contact

Brand: Holiday Lydian

Legal entity: Lydian AI Inc

Registration number: P26000032676

Headquarters: Jacksonville Beach, Florida, United States

Registered address: 2309 Beach Blvd, Jacksonville Beach, FL 32250, United States

Governing law: State of Florida, United States

Phone: +1 813 458 5004

Security contact: security@holiday.ailydian.com

1. Encryption in transit

All traffic to and from the platform is served over HTTPS using TLS. This protects your account credentials, booking details and other data as they travel between your device and our services.

2. Payment security (PCI-DSS)

Card payments are processed by Stripe, a PCI-DSS Level 1 certified payment provider. Card details are captured directly by the processor; Holiday Lydian does not store your full card number. This keeps sensitive cardholder data out of our systems.

3. Access controls

  • Access to production systems and personal data is limited to authorised personnel on a need-to-know basis.
  • Administrative interfaces require authentication and are protected behind access controls.
  • Passwords are stored as salted hashes, never in plain text.
  • We log and monitor access to sensitive operations.

4. Infrastructure and monitoring

The platform runs on managed infrastructure with routine patching, backups and monitoring. We separate responsibilities across services so that a problem in one area is contained, and we review our configuration as the platform evolves.

5. Responsible disclosure

If you believe you have found a security vulnerability, please report it privately to our security contact before disclosing it publicly. Give us a reasonable opportunity to investigate and remediate. We commit to acknowledging your report, keeping you informed, and not pursuing legal action against good-faith research that respects the rules below.

6. Rules for good-faith research

  • Do not access, modify or delete data that does not belong to you.
  • Do not degrade service (no denial-of-service, spam or automated high-volume testing).
  • Use only test accounts you control; do not target other users.
  • Do not use social engineering, phishing or physical attacks against our staff or facilities.
  • Give us reasonable time to fix an issue before any public disclosure.

7. What to include in a report

A clear description of the issue, the affected URL or endpoint, reproduction steps, and any proof-of-concept that helps us confirm and fix the problem quickly. Please encrypt sensitive details where possible.

8. Scope

This program covers the holiday.ailydian.com platform and its official subdomains. Issues in third-party services we integrate (such as the payment processor) should be reported to those providers, though we are happy to help coordinate.

Report a vulnerability

Send security reports to our security contact. Please follow the good-faith rules above and allow us time to remediate before public disclosure.

Last updated: 27 July 2026. Our measures are reviewed regularly as the platform evolves.