Skip to content
OmniGuest

Security & privacy

Isolation, private AI and a full audit trail — as architecture, not as a checkbox.

Hotels hand us guest names, stays, preferences and conversations. OmniGuest is designed to meet GDPR, SOC 2 and PCI-DSS SAQ-A-EP requirements; the controls below describe how the platform is built today, not what a certificate promises.

Passkeys first. Passwords as the exception.

Every staff member signs in with a phishing-resistant passkey; two-factor codes and session control are one screen away. Administrators see who is signed in where and can end sessions remotely.

OmniGuest security settings with password, two-factor authentication and passkeys
  • Tenant isolation: one schema per enterprise

    Each hotel group runs in its own PostgreSQL schema on a dedicated application node. There are no shared guest tables.

    • Schema-per-enterprise with per-hotel scoping inside
    • Enterprise tiers with dedicated database instances available
    • Cross-tenant access is impossible by construction, not by filter
  • Private AI infrastructure

    Language, vision and speech models run on OmniGuest GPUs. Prompts, documents and guest data never reach a public AI API.

    • Open-weight models served in-house behind a private gateway
    • No training on customer data — ever
    • Retrieval index per enterprise, deleted with the tenant
  • Phishing-resistant authentication

    Passkeys (WebAuthn) are the primary login. Passwords with TOTP remain available for transition.

    • Short-lived signed tokens issued by a central identity service
    • Custom roles and permissions per department and hotel
    • Session overview and remote sign-out for administrators
  • Audit trail

    Reads and writes on guest data, every sent message, every AI draft and every PMS writeback are recorded with actor and time.

    • Immutable audit log per enterprise
    • Exportable for compliance reviews
    • Alerts on unusual access patterns
  • Encrypted credentials

    PMS and mailbox credentials are encrypted at rest with keys managed by the control plane and never exposed to application nodes in plain text logs.

    • Envelope encryption for integration secrets
    • OAuth wherever the provider supports it
    • Rotation without downtime
  • Hosting in Europe

    Production runs in EU data centres. Customer data does not leave the region for processing, including AI inference.

    • EU regions for application, database and inference
    • Encrypted transport everywhere (TLS 1.2+)
    • Encrypted backups with tested restores
  • Retention and deletion

    Conversations, newsletters and profiles follow retention rules per hotel. Deletion requests are executed across all stores, including search and AI indexes.

    • Configurable retention per data category
    • Right-to-erasure workflow with confirmation
    • Tenant offboarding removes schema, files and indexes
  • PMS writeback with approval

    Nothing is written into your PMS without a rule allowing it. An approval matrix per hotel decides what goes back automatically and what needs a human.

    • Queue-based writeback with retries and visibility
    • Field-level rules: notes, preferences, profile updates
    • PMS always wins on conflicts
  • Compliance posture

    Designed to meet GDPR, SOC 2 and PCI-DSS SAQ-A-EP requirements. We provide a data processing agreement, sub-processor list and architecture documentation for your security review.

    • DPA and sub-processor list on request
    • Security questionnaire support for enterprise buyers
    • Payment card data is never stored by OmniGuest (planned payments module uses tokenisation)

A note on certifications

OmniGuest is designed to meet GDPR, SOC 2 and PCI-DSS SAQ-A-EP requirements. We do not claim certifications we do not hold. For your vendor assessment we provide architecture documentation, a data processing agreement, the sub-processor list and answers to your security questionnaire — ask for them in the demo.

Bring your security questionnaire.

We answer it in the first call, with the architecture on screen. Isolation, AI hosting, retention — every question has a concrete answer.