Property isolation
Operational data is scoped to the authenticated hotel/property context. Staff APIs resolve the signed-in employee’s property before reading or changing hotel work.
SECURITY OVERVIEW
This page describes controls implemented in the current product and release process. It is not a certification report, penetration-test claim or contractual security addendum.
Operational data is scoped to the authenticated hotel/property context. Staff APIs resolve the signed-in employee’s property before reading or changing hotel work.
Permissions are checked on server routes for operations, team management, knowledge, branding, analytics, diagnostics and billing. Hidden navigation is not treated as authorization.
Guest-facing property portals are separate from authenticated staff workspaces. Publishing a guest portal does not expose staff routes or management APIs.
Database service credentials, AI keys, billing secrets, communications credentials, push keys and monitoring credentials remain server-side and are not intentionally placed in browser or native bundles.
Guest and staff AI use hotel-approved published knowledge with visibility controls. Unsupported hotel policy questions are designed to fail closed rather than invent property-specific facts.
Guest service creation is property-scoped and includes clarification, validation and duplicate-request controls. Staff work keeps lifecycle history and ownership rather than relying on silent overwrites.
An employee must prove possession of a phone number through verification before operational text alerts can be enabled for that number.
Native push and SMS delivery attempts are performed server-side and written to a delivery audit trail with provider outcome context rather than exposing provider credentials to the device.
Commercial access is enforced at the organization level. Stripe webhook events are signature-verified before subscription lifecycle data can change access state.
OPHOZ’s error transport is designed to send sanitized error/route context rather than automatically attaching guest conversations, hotel request bodies or query strings.
Management can review property launch, commercial and provider readiness before go-live. Optional integrations remain visibly unconnected until provisioned and tested.
iOS and Android builds are compiled in CI, but store release stays gated on real signing, physical-device tests, push, deep links, privacy declarations and reviewer access.
CURRENT STATUS
For a founding-hotel deployment, OPHOZ can review the enabled architecture, providers and pilot-specific data handling before launch.