OPHOZ
Book a pilotPilot

SECURITY OVERVIEW

One hotel’s operation should stay one hotel’s operation.

This page describes controls implemented in the current product and release process. It is not a certification report, penetration-test claim or contractual security addendum.

Property isolation

Operational data is scoped to the authenticated hotel/property context. Staff APIs resolve the signed-in employee’s property before reading or changing hotel work.

Server-enforced roles

Permissions are checked on server routes for operations, team management, knowledge, branding, analytics, diagnostics and billing. Hidden navigation is not treated as authorization.

Guest/staff separation

Guest-facing property portals are separate from authenticated staff workspaces. Publishing a guest portal does not expose staff routes or management APIs.

Server-only secrets

Database service credentials, AI keys, billing secrets, communications credentials, push keys and monitoring credentials remain server-side and are not intentionally placed in browser or native bundles.

Approved knowledge

Guest and staff AI use hotel-approved published knowledge with visibility controls. Unsupported hotel policy questions are designed to fail closed rather than invent property-specific facts.

Request safeguards

Guest service creation is property-scoped and includes clarification, validation and duplicate-request controls. Staff work keeps lifecycle history and ownership rather than relying on silent overwrites.

Verified employee SMS

An employee must prove possession of a phone number through verification before operational text alerts can be enabled for that number.

Notification audit

Native push and SMS delivery attempts are performed server-side and written to a delivery audit trail with provider outcome context rather than exposing provider credentials to the device.

Billing integrity

Commercial access is enforced at the organization level. Stripe webhook events are signature-verified before subscription lifecycle data can change access state.

Monitoring minimization

OPHOZ’s error transport is designed to send sanitized error/route context rather than automatically attaching guest conversations, hotel request bodies or query strings.

Release diagnostics

Management can review property launch, commercial and provider readiness before go-live. Optional integrations remain visibly unconnected until provisioned and tested.

Native release discipline

iOS and Android builds are compiled in CI, but store release stays gated on real signing, physical-device tests, push, deep links, privacy declarations and reviewer access.

CURRENT STATUS

We do not claim certifications we have not earned.

For a founding-hotel deployment, OPHOZ can review the enabled architecture, providers and pilot-specific data handling before launch.