Security

Built so that one manager's data can never leak into another's.

Tenant isolation in the database

Every record carries the organisation it belongs to, and the database itself enforces who can read it. Not the application: the database. We test this on every deploy with accounts from two organisations trying to read each other's data.

Roles that see only their slice

Administrators see their organisation. Owners see their properties' calendar, money and approvals. Staff see tasks and stays with no amounts. Guests see only their own stays.

No passwords, no card numbers

Sign-in is by one-time code to your email. Guest payments run through Stripe Checkout; card details never reach our servers. We never store an owner's card.

No access to your Airbnb account

We read the calendar feed Airbnb publishes and the emails you forward. We never ask for your Airbnb password and never log in as you.

Encrypted, backed up, logged

Data is encrypted in transit and at rest, backed up daily, and every approval, statement lock and money movement is written to an activity log your administrators can read.

Infrastructure

Supabase (Postgres, US East), Vercel, Resend and Stripe. Each is SOC 2 audited. HoztSync itself is a small, in-house codebase with no third-party channel connectors in the path of your bookings.

Found something? security@hoztsync.com. We answer within one business day.