Security Report AI
Security
The controls listed below are implemented and verified in the product today. Nothing here is a certification, an audit result or a compliance statement.
Verified controls
- • Tenant isolation: every record belongs to one hotel workspace, and access is decided by database row-level security based on workspace membership — not by the interface. Accounts from one workspace receive empty results for another workspace's data.
- • Least privilege: anonymous visitors hold no privileges on any application table and cannot execute internal database functions. Signed-in accounts hold read-only access to commercial tables; writes go through server-side checks.
- • Role separation: owner, manager and officer roles carry different write permissions, enforced in database policy rather than in the client.
- • Private document storage: uploaded SOP files live in a private bucket, are served only through short-lived authorised links, and their storage paths contain opaque identifiers only — never a property name.
- • Invitation security: invitation links are stored only as SHA-256 hashes, are single-use, expire, are bound to the invited email address and can be revoked.
- • Audit trail: incident status changes and reviews are recorded as append-only events with actor and timestamp.
- • Platform separation: platform administration is a separate role that sees account-level metadata and counts, not incident content or uploaded documents.
- • Account security: email verification is required, self-service sign-up is closed, passwords are checked against known-breached password lists by the authentication provider, and password reset is self-service.
- • Data export: a signed-in user can download a machine-readable copy of the records their account is authorised to read, generated under the same access rules as the app.
- • Human review by design: AI output is a draft, and the product records who reviewed a report before it is closed.
Not claimed
The product holds no ISO, SOC 2 or PCI certification, has not undergone an independent security audit or penetration test, and no compliance status is asserted. Encryption, availability and incident-response commitments are those of the underlying hosting providers and are not offered as contractual guarantees during the pilot.
Reporting a vulnerability
- • The operating entity, its registered address, VAT number and published contact addresses are not confirmed yet. They are provided in writing to each pilot customer before any data is entered, and will be listed here once registered.
This page is a factual description of implemented controls at the time of writing and is updated as the product changes.