Security & trust

Infrastructure-grade isolation, applied to hospitality.

Every property runs on its own dedicated, isolated environment — the BOX model — with GDPR-aligned data residency and encryption in transit and at rest.

Compliance posture

Three frameworks, stated honestly.

No badges we haven't earned — here is exactly where each framework stands today.

GDPR · aligned

GDPR-aligned by design

Each property's data is isolated and resident in-region — EU/EEA or GCC, per your deployment — encrypted at rest and in transit. A Data Processing Agreement is signed before kickoff, data-subject-access tooling is built into the dashboard, and every transfer outside the EU runs under Standard Contractual Clauses.

SOC 2 · roadmap

SOC 2 — on the roadmap

We are building toward a SOC 2 examination. The controls below — access management, change management, monitoring, incident response — are already in place. We will not claim a report before an auditor has issued one.

ISO 27001 · roadmap

ISO 27001 — on the roadmap

Our information-security practices are being mapped to the ISO 27001:2022 control set. Certification is a future step, not a current claim — we are happy to walk your team through the controls we run today.

The BOX model

Dedicated infrastructure per property. No multi-tenancy.

Where the industry default is one database for thousands of properties, every AURI property is its own isolated environment — so cross-property data leakage is an architectural impossibility, not a promise.

01

Dedicated database

One database per property. No shared rows, no shared schemas. Encrypted at rest with Google Cloud default AES-256.

02

Isolated app instance

Each property runs in its own pinned namespace. No data path is shared across properties at runtime.

03

Property-bound backups

Daily encrypted backups with point-in-time recovery and a retention policy configured per property. Restores are audited.

Controls

The controls, grouped and named.

No marketing language — the actual controls we run, grouped by area, with more detail on request.

01 — Data

Data security

  • AES-256 encryption at rest (Google Cloud default)
  • App-level AES-256-GCM on VIP guest PII
  • TLS 1.2+ in transit, HTTPS enforced
  • EU/EEA data residency, regional pinning
  • Daily encrypted backups with defined retention
  • Point-in-time recovery within the retention window
  • Cryptographic erasure on contract termination
02 — Identity

Identity & access

  • Optional multi-factor authentication (TOTP) for staff accounts
  • Role-based access control with sensible defaults
  • Session policies configurable per role
  • 32-byte session tokens with bounded lifetimes
  • Access reviews on a regular cadence
03 — Application

Application security

  • Automated test suite run on every release
  • Static analysis + dependency scanning in CI
  • Secrets held in a managed vault, rotated regularly
  • Admin actions audit-logged and immutable
  • Automated security checks on every change — no external audit is claimed
  • Coordinated vulnerability-disclosure path
04 — Operations

Operational security

  • 99.5% monthly uptime target, externally monitored
  • Incident-response on-call rotation
  • Defined recovery objectives, tested periodically
  • Change-management process with post-mortems
  • Status visibility for customers
  • Prompt notification on any major incident
05 — Build

How it's built and checked

  • Containerised builds (Docker), infrastructure as code (Terraform)
  • CI pipeline (GitHub Actions) runs on every change
  • Automated tests + static analysis gate every release
  • Security linting and dependency scanning in the pipeline
  • Failing checks block deployment
  • The same pipeline discipline builds this site and the product
06 — Privacy

Privacy controls

  • DPA signed before kickoff, no exceptions
  • Data-subject-access tooling in the dashboard
  • Right-to-erasure with verifiable proof
  • Sub-processor list available, 30 days' notice of changes
  • Non-EU sub-processor transfers covered by EU SCCs
  • Your data is never used to train any model
For your IT & legal team

Documents, on request.

What we can share today, and what is on the way — ask and we'll tell you exactly which is which.

Available today

BOX architecture write-up

The technical description of the per-property dedicated-infrastructure model — for your CTO. No marketing.

Available today

DPA + service agreement

Our Data Processing Agreement and service-agreement templates, SCCs included, ready for your counsel to review.

On the roadmap

Trust pack

Sub-processor list and security overview today; penetration-test, SOC 2, and ISO 27001 artefacts as those programmes complete. Shared under NDA.

Security review

We will sit in your security review.

Founder plus the engineer who built the isolation model on the call — bring your CISO, your DPO, your auditor.

Founder + security engineer Bring your auditor No NDA required to talk