Security & compliance

You're hosting guest PII and passports. We treat it that way.

This is a trust product before it's a feature list. Here's the posture in plain language.

Data protection (PDPA / GDPR)

We align with Thailand's PDPA as our primary framework and GDPR for EU guests and properties — lawful basis for processing, data-subject access/erase/export rights, a signable data-processing agreement per property, defined retention and deletion periods, and a breach-notification process.

Guest PII & passport data

Passport and immigration data are treated as sensitive categories: encrypted at rest and in transit, isolated per property, accessed on least-privilege, with every access logged.

Payments & PCI scope

We never store full card numbers — only the last four digits, as the production system already does. Real card handling runs through a PCI-DSS compliant processor, keeping the PMS itself out of PCI scope as far as possible.

Tenant isolation

Each property's data is isolated at the database level. A request for one property is never able to read another's — enforced on every request, not just at the UI layer.

Identity & access

Google + TOTP multi-factor sign-in, rate-limiting, session hardening, and role-based permissions on every surface.

Backups & restore

Grandfather-father-son backup rotation per property, with restore drills — not just backups nobody has tested.

Data residency

Hosted by default. A local-data option exists for properties with sovereignty requirements, available on our Multi-property plan.

Audit log

A full, unalterable audit trail of financial and configuration changes — extended to platform-level actions, not just in-property ones.

Questions about your specific compliance needs?

Talk to us before you sign anything — we'll tell you plainly what's ready today and what's on the roadmap.