HospitalityOS
Security

Security and trust by design.

HospitalityOS is built with security, privacy, and trust as foundational principles — not afterthoughts.

Pillars

How we approach security

Tenant Isolation
Organizations never see each other's data. Row-level security enforces isolation at the database level.
Role-Based Access
Granular permissions per role, per property, per portfolio. Users see only what they need.
Auditability
Every action is logged and traceable. Operational history is preserved for accountability.
Data Minimization
We collect and process only what is necessary. Guest PII is minimized and protected.
Secure Integrations
Signed, authenticated integrations. Credentials are never stored in generic entity fields.
Privacy Boundaries
Guest data, staff data, and operational data are separated by design.
Cross-Vertical Consent
Cross-vertical cooperation requires explicit consent and defaults to OFF.
Spatial-Data Provenance
Every spatial fact has a provenance type — measured, detected, declared, inferred, or verified.

What we do not claim:

  • We do not claim ISO 27001, SOC 2, PCI DSS, or GDPR certification unless verified.
  • We do not claim "100% secure."
  • We only claim certifications that are actually held.

Trust is built into every layer.

From everyday operations to spatial guest experiences and connected journeys, HospitalityOS is built to grow with your property.

We use essential cookies.