Security and trust

Controls designed into the operating model.

StayOS uses tenant and property boundaries, role-based access, audited sensitive operations, guarded administration, and careful handling of private data.

Security foundations in the implemented platform.

Access control

Role, permission, property, tenant, and platform-admin checks protect operational boundaries.

Audited operations

Sensitive administrative and hotel actions produce bounded, redacted audit context.

Data separation

Tenant context and property access are enforced before scoped model resolution.

Safer content

CMS rich text, uploads, previews, redirects, and public forms use explicit security controls.

Responsible disclosure

If you believe you have found a security issue, contact the address listed on this page. Please avoid accessing, modifying, or retaining data that is not yours. We will acknowledge legitimate reports and coordinate next steps.

This page describes implemented safeguards and does not claim certifications, guarantees, or service levels that have not been independently verified.