Trust · Security · Privacy
Stated plainly.
Hotels hand us trading data and guest-adjacent data. This page is exactly how we treat it — what is true today, what is still on the roadmap, and the difference between the two. No invented certifications, no “bank-grade” anything. We’re a governance consultancy’s own product; this page has to survive our own profession reading it.
How the AI uses your data
The AI is a guest in your data, and it’s treated like one.
HotelStack’s intelligence features run on frontier models from Anthropic, with Google models for image generation. Four rules govern every interaction:
- The model never queries our databases — the server hands it a minimum, role-scoped context.
- What it can see is what you can see: role permissions apply to the AI’s context, not just your screen.
- Its writes are proposals — a human approves every change before it lands.
- Every call and every action goes to the append-only audit log.
Two things said plainly, because a careful reader will ask. First: AI inference is processed by our model providers in the United States — your application data lives in Sydney, but the context slice sent to a model crosses the border for the duration of the request. An onshore option is designed for clients who need it. Second: we are formalising our data-use terms with each AI provider, and until that work is done we won’t publish a “your data never trains a model” badge. When we can evidence it, it will appear here first.
WHAT ACTUALLY REACHES A MODEL
- ViP OPERATE
- Venue context — POS summaries, bookings, occupancy, costs — scoped to your role. No individual guest profiles are sent by design.
- HiP / AiP INVEST
- Assumptions, benchmarks and page-level excerpts — deliberately minimal. Bulk documents and raw models stay behind.
- All products
- POS data arrives as aggregates; we hold no cardholder data anywhere, so none can reach a model.
The posture ledger
What we can prove, and what we’re still building.
A specific, honest posture reads stronger than a badge wall. Everything below is written the way we’d want a vendor to write it to us.
TRUE TODAY
Hosted in Australia
Application and database layers run in DigitalOcean’s Sydney region (syd1) for every HotelStack product.
Tenant isolation on every path
Row-level tenant isolation is enforced in the application layer on every data access — including every AI tool call. The same gate guards the UI and the model.
AI never touches the database
Models don’t query our systems. The server assembles the minimum context a question needs and passes only that slice to the model.
AI writes wait for a human
When an AI proposes a change, it lands as a pending action. A person approves it — or doesn’t. Nothing self-executes.
Everything is on the record
An append-only audit log records every data change and every AI action — actor, before and after, outcome.
No payment card data
HotelStack ingests POS trading as summary aggregates. We do not store or process cardholder data, by design.
Presence sensing without identity
Presence and occupancy analytics use environmental and network signals and are reported as aggregates — no individual is identified or tracked as a person. This is an architectural choice, not a setting.
Hardened transport
TLS 1.2+ with modern ciphers and HSTS across our public surfaces; legacy protocols are rejected.
Clean secret history
A full-history scan across our entire engineering estate — 33 repositories, 11,000+ commits — found no committed credentials, and scanning now gates new commits.
ON THE ROADMAP — NOT YET TRUE
SOC 2 & ISO 27001
Self-assessed today, not attested. We publish no badge we can’t evidence; formal alignment is on the roadmap and our gap analysis is honest about the distance.
Independent penetration testing
An internal, evidence-chained red-team programme is authorised and standing up. No external penetration test has been commissioned to date — when one is, we’ll say so here.
Multi-factor authentication
MFA enforcement is committed, starting with high-privilege accounts. Until it ships, we won’t claim it.
Formal incident response
A documented, tested incident-response programme is being built. Today, incidents would be handled by the engineering team directly — we’d rather tell you that than gesture at a plan that doesn’t exist yet.
Published retention & deletion policy
Deletion on account closure is our operating commitment; the formal, published retention schedule is in progress.
Onshore AI inference
An Australian-region inference option for sovereignty-strict clients is designed and offered on request — built when a client needs it.
Privacy
Guests didn’t choose us. We act like it.
Your guests have a relationship with your hotel, not with HotelStack — so the platform is built to need as little of their data as possible. Trading arrives as aggregates. Presence analytics are non-biometric. Where personal information is handled, we work to the Australian Privacy Principles, and our product decisions track the OAIC’s enforcement positions and New Zealand’s Biometric Processing Privacy Code.
Ask us the hard questions.
Security questionnaires, data-flow diagrams, the unvarnished answer on any line of this page — we’d rather have that conversation early.
Talk to us