TRUST & SECURITY

    Security at Hospitia

    We handle sensitive hotel data — photos, compliance scores, brand standards. We take that responsibility seriously.

    Data protection

    Encryption at rest

    All inspection data, photos, and compliance reports are encrypted at rest using AES-256. Sensitive contract documents use an additional application-layer encryption key, separate from infrastructure credentials.

    Encryption in transit

    All data transmitted between clients and our servers uses TLS 1.2 or higher. Our API endpoints enforce HTTPS exclusively — no plaintext connections are accepted.

    Data isolation

    Each brand's configuration and each property's inspection data are logically isolated. Cross-tenant data access is prevented at the application and database query layers.

    Access controls

    Role-based access controls limit what each user can see and do. Brand admins can only access their own brand's properties. Reviewers can only access assigned inspection sessions.

    Infrastructure

    Hospitia's infrastructure runs on modern cloud platforms with automated backups, uptime monitoring, and alerting. Database backups are taken daily and retained for a minimum of 30 days. We use environment-isolated secrets management — credentials are never committed to source code.

    Photo uploads are stored in private object storage with signed URLs. Photos are never publicly accessible without a time-limited, authenticated download link.

    Compliance posture

    We are currently building toward SOC 2 Type II attestation. Our engineering practices — audit logging, principle of least privilege, encrypted storage, documented incident response — are aligned with SOC 2 Trust Service Criteria.

    If you have specific compliance requirements (GDPR, CCPA, HIPAA adjacent), contact us at security@hospitia.tech to discuss. We are happy to review a DPA or security questionnaire.

    Responsible disclosure

    If you discover a potential security vulnerability in Hospitia, please report it responsibly to security@hospitia.tech. We will acknowledge your report within two business days and work to resolve confirmed issues promptly. We do not pursue legal action against good-faith security researchers.

    Security contact

    security@hospitia.tech · For vulnerability reports and security enquiries