The site traffic system connects into your network — and the IT department rightly asks what that does to security. The answer is built into the design: no PSA component is directly reachable from the internet, the database runs locally and is not exposed externally, and the system's components sit in a dedicated, separate network (DMZ / VLAN), so a potential attack doesn't spread across the site. Service access runs only through a VPN, not through an open port.
It can be deployed in two ways, depending on your policy: on-premise in your DMZ behind a firewall you manage, or as a standalone unit with its own mobile connection where you don't want to let the system into the corporate network at all. Reservation data from the public portal flows in through an encrypted tunnel, not by direct access.
It's a design aligned with NIS2 principles, not a certificate — the operator is the one who meets the directive, and we supply technology that makes that easier, not harder.