Trust centerGrandOS index

Security as a system boundary — not a slogan.

GrandOS separates hotels, constrains AI, avoids raw card data and logs changes. Live integrations activate only after verified tests.

Least privilege by default
01Card dataHosted payment fields
02AIActions require approval
03HotelsIsolated access
01

Hotel data stays separated

Every read and write must be tied to the right hotel and an authorised identity.

  • Ownership checks at the data layer
  • Private admin surface
  • Audit history for account changes
02

Funds do not pass through our code

Raw card numbers go directly to the hotel’s payment provider. GrandOS stores only the required status and reference.

  • Stripe-hosted payment fields
  • The hotel is the merchant
  • Refunds require authorisation
03

AI has hard boundaries

The assistant can read approved sources and prepare work, but cannot move money, change a rate or contact guests on its own.

  • Source-grounded knowledge
  • Human approval
  • Traceable suggestions
04

Production is a gate, not a label

The public site is a development environment. A real hotel remains blocked until identity, data responsibility, recovery and every selected connection have passed an accountable launch review.

  • Hotel roles and access recovery
  • Data-processing and subprocessor terms
  • Backup restore and incident drill

Trust center · GrandOS

Your next step
starts here.

Read the privacy notice