Product
Who it’s for
DocumentationPricingAcademy Log in
Book a demo WhatsApp
ESEN

Safeguarding your information

What Containn keeps and what it doesn't: the digital seal, the e.firma, bank accounts, permissions and how each hotel's information is kept separate.

What it is

This article explains which sensitive information Containn keeps, which it doesn't, and who can see what it does keep. It only describes what the system does today.

The digital seal (CSD)

The Certificado de Sello Digital (CSD, the digital seal certificate used to stamp CFDI, Mexico's electronic tax invoices) is uploaded in Settings → CFDI Invoicing (SAT): the .cer file, the .key file and the key's password. Before sending it, the system checks that the .cer and .key are a matching pair and belong to the hotel's RFC (Mexican tax ID). It is then handed to the authorized certification provider, which holds it in custody. The database doesn't store the private key or its password.

Canceling an invoice requires signing with the same seal. If you leave the Also save for cancelling invoices box checked when you upload it, the seal is kept on the platform's server, never in the database, and you aren't asked for it again on each cancellation. If you uncheck it, you're asked for it when you cancel, it's used only for that signature, and it isn't stored. The box comes checked: the decision is yours.

Only someone with the Facturación CFDI (SAT) permission, tagged as critical, can upload the seal.

The e.firma is never requested

Containn never asks for the hotel's e.firma (the advanced electronic signature issued by the SAT, Mexico's tax authority). You need it to obtain the CSD from the SAT, but it isn't uploaded. That's why the electronic accounting files come out unsigned: your accountant signs them with the hotel's e.firma and submits them through the Buzón Tributario (the SAT's taxpayer mailbox).

Bank accounts

For each bank account, only the last four digits are kept. Even if the full number is typed, the rest is discarded.

Who sees what

  • Each hotel keeps its own books: chart of accounts, pólizas (the Mexican term for journal entries), periods and bank accounts. Every time someone looks something up or changes it, the system checks that the person belongs to that hotel or to the group that controls it, and a ledger account from another hotel can't be used in your pólizas. The platform's authorized staff also have access.
  • Within the hotel, access is granted per person in My Team: the Containn section and its five permissions. Reopening a month is a special permission nobody has until it's granted.

What is never deleted

A póliza is never deleted: it's canceled, and the canceled one is kept. A signed day keeps its sheet exactly as it was signed, and every reopening keeps who, when and why.

What to review in your hotel

  1. In My Team, check who has the Containn section and who has the permissions tagged as critical.
  2. Grant Reabrir un mes contable cerrado (reopen a closed accounting month) only to whoever should have it.
  3. In CFDI Invoicing (SAT), decide whether the seal is saved for cancellations or requested each time.
  4. In Bancos (banking), enter only the last four digits of each account.

Related articles

Didn’t find what you were looking for?

Message us on WhatsApp and we’ll reply the same business day.

Book a demo