Trust centerGrandOS index
Security as a system boundary — not a slogan.
GrandOS separates hotels, constrains AI, avoids raw card data and logs changes. Live integrations activate only after verified tests.
Least privilege by defaultHotel data stays separated
Every read and write must be tied to the right hotel and an authorised identity.
- Ownership checks at the data layer
- Private admin surface
- Audit history for account changes
Funds do not pass through our code
Raw card numbers go directly to the hotel’s payment provider. GrandOS stores only the required status and reference.
- Stripe-hosted payment fields
- The hotel is the merchant
- Refunds require authorisation
AI has hard boundaries
The assistant can read approved sources and prepare work, but cannot move money, change a rate or contact guests on its own.
- Source-grounded knowledge
- Human approval
- Traceable suggestions
Production is a gate, not a label
The public site is a development environment. A real hotel remains blocked until identity, data responsibility, recovery and every selected connection have passed an accountable launch review.
- Hotel roles and access recovery
- Data-processing and subprocessor terms
- Backup restore and incident drill
Trust center · GrandOS