Trust architecture

Security & Data Principles

This page describes design principles, not a certification or contractual security guarantee.

Least privilege

Access to operational systems and data should be limited to the permissions required for the relevant role, property, tenant or automated process.

Auditability

Consequential automated and human actions should be attributable and reviewable through appropriate event, decision and audit records.

Sensitive-data separation

Highly sensitive identity or document data should be separated from general operational history and subject to stricter access and retention controls.

Data minimization

Collect data because it serves a defined operational, contractual, legal or analytical purpose — not merely because it can be collected.

Useful history without uncontrolled identity retention

Where possible, long-term analytical and AI-improvement data should be aggregated, pseudonymized or de-identified so that operational learning does not depend on retaining raw sensitive identity data.

Provider independence

Core business knowledge and permitted historical data should remain exportable and should not become unnecessarily locked into one OTA, messaging provider, AI vendor or infrastructure provider.

Human control for high-risk actions

Payments, refunds, legal commitments, security-sensitive actions and other consequential decisions should remain behind explicit permissions and, where appropriate, human approval gates.

Responsible improvement

Security, privacy and data governance requirements should be reviewed as products, customer types, jurisdictions and data uses expand.