Trust & security

The postureyour auditor expects.

HotelOS handles guest PII, payment tokens, payroll signals and the general ledger. Treat us like a finance system, because we are one.

This page is the single source of truth for our security posture, data architecture, and compliance status. We publish the same detail to procurement teams that we publish here — no hidden caveats, no certification asterisks.

Certifications & frameworks

Where we stand
on the paperwork that matters.

Certification 01

SOC 2

In progress

We are working with an independent auditor on Type I scoping. Type II observation will follow. We will publish each milestone here as it lands — no calendar promises while we are building the controls properly.

Certification 02

PCI DSS

Out-of-scope architecture

We do not store, process, or transmit cardholder data. Tokenisation runs through your existing PSP (Adyen, Stripe, Mews Payments, Worldpay) and tokens are referenced by handle only.

Certification 03

GDPR · APPI · PDPA

Standard Article 28 DPA

Standard contractual clauses, sub-processor list, and right-to-export endpoints available on request. Data Protection Officer at [email protected].

Certification 04

ISO 27001

Future scope

ISMS scope is being defined alongside SOC 2 work. ISO 27001 is on the longer-term roadmap; we will signal a target window once Type I lands.

Data architecture

How we hold
your operating data.

Hosting & residency

Per-tenant residency election at provisioning across US (Virginia), EU (Frankfurt), and APAC (Singapore). Stateful data, object storage and backups stay in the elected region. Edge compute is regionally pinned for residency-sensitive workloads. No cross-region transfer without your written instruction.

Encryption

AES-256 at rest, TLS 1.3 in transit. KMS-managed keys per tenant. BYOK on enterprise tier; HYOK on the roadmap for regulated groups.

Identity & access

SAML 2.0 and OIDC against Okta, Microsoft Entra and Google Workspace. SCIM provisioning. Role-based access scoped to property, brand, and folio. Break-glass with session recording and post-session review.

Audit trail

Append-only, cryptographically chained event log across every product surface. Exportable in CSV or Parquet for your auditor. 7-year default retention; configurable per jurisdiction.

Backup & resilience

Continuous WAL backup, point-in-time recovery, daily snapshots replicated to a second region. Targeted RTO of 4 hours, RPO of 5 minutes; we will publish measured numbers once the platform has lived through real production seasons.

Sub-processors

A current sub-processor list is available on request and will be published openly as the catalogue firms up. We commit to 30-day change notification on material additions, with no cross-jurisdiction transfer outside the published list without written consent.

Operating policies

How we behave
when something goes wrong.

Penetration testing

Scoping our first independent third-party penetration test now. Findings and remediation will be published here as the engagement completes.

Vulnerability disclosure

Coordinated disclosure policy in place — safe-harbour for researchers acting in good faith. Reach us at [email protected].

Bug bounty

A private bug-bounty programme is on the roadmap, opening alongside SOC 2 Type I. Public expansion follows once we have lived through it.

Breach notification

Commitment to notify within 72 hours of a confirmed material incident, with a written remediation plan inside 14 days. Codified in every customer DPA.

Cyber insurance

Cyber liability and professional indemnity coverage is available on customer request, sized to portfolio and procurement requirements. Summary shared under NDA.

Sub-processor controls

Sub-processors are security-reviewed before onboarding, with a documented exit plan for tier-one services. Annual review cadence as the catalogue grows.

Procurement is welcome

Hand us your security questionnaire.

We answer enterprise security questionnaires (CAIQ, SIG-Lite, custom) inside five business days. The trust pack — SOC 2 letter, DPA, sub-processor list, pen-test summary, insurance summary, BCP/DR plan — is available under NDA in one click.