Security
How HODStay is built to keep your hotel data and team access appropriately controlled.
Tenant isolation
Each hotel workspace in HODStay is isolated at the data layer. One tenant's rooms, guests, reservations and payments are not accessible to any other tenant on the platform.
Role-based access control
Staff members are assigned roles — receptionist, housekeeping, accountant, maintenance or owner. Each role is granted access only to the pages and actions appropriate to their work. Role configuration is managed by the hotel owner or account administrator.
Authenticated sessions
Access to all HODStay workspaces requires email and password authentication. Sessions are managed server-side. HODStay does not store plain-text passwords.
Audit history
Key operational events — including check-ins, checkouts, payment records, room status changes and staff actions — are recorded in a chronological audit log accessible to hotel management.
Infrastructure
HODStay runs on managed cloud infrastructure with automated backups. Billing verification is performed server-side. No payment credentials or secret keys are exposed to the browser.
What we do not claim
We do not claim ISO 27001 certification, PCI DSS compliance, guaranteed uptime, military-grade encryption, or absolute data security. Security is an ongoing practice, not a fixed state.
Reporting a concern
If you discover a potential security issue in HODStay, please contact us through the contact page so we can investigate promptly. Do not publicly disclose the issue before giving us an opportunity to address it.