Start free — no card
14-day trial
Try it →
Trust · Security · Compliance

How Hostella protects your data.

We handle bookings, guest messages, payment records, and PMS credentials for villa operators across the EU and APAC. Here's everything our compliance teams want to know — published openly.

SOC 2 Type II
Planned
Controls mapped to AICPA TSC · audit not yet scheduled
GDPR
Aligned
DPA available on request
Encryption
AES-256
TLS 1.3 in transit · GCM at rest
Tenant isolation
Org-scoped
Role-gated APIs · recurring security audits
Sub-processors

Who we trust with your data

We publish every third-party service that processes customer data on our behalf. Sub-processor changes are announced 30 days in advance via this page and email to billing contacts.

Vercel Inc.
Global (EU/US POPs)
SOC 2 Type IIISO 27001
Application hosting, edge CDN, serverless compute
Data shared: Application requests, IP addresses, browser metadata
Supabase Inc.
Northeast Asia (Tokyo)
SOC 2 Type IIHIPAA-readyGDPR DPA
Primary PostgreSQL database, authentication, storage
Data shared: All customer data (org records, reservations, guests, messages)
Anthropic PBC
US
SOC 2 Type IIAPI data not used for training
AI agent inference (Claude models)
Data shared: Guest messages, property knowledge base (only at inference time)
OpenAI, L.L.C.
US
SOC 2 Type IIAPI data not used for training
AI inference for the operator support copilot and voice chat
Data shared: Operator support-chat messages (only at inference time)
ElevenLabs Inc.
US
SOC 2 Type IIGDPR DPA
Voice AI for the website voice assistant
Data shared: Voice-session audio and transcripts (visitors who opt in)
Resend (Plus Five Five, Inc.)
US/EU
SOC 2 Type IIGDPR DPA
Transactional email delivery
Data shared: Recipient email addresses, email content
Stripe, Inc.
US/EU
PCI-DSS Level 1SOC 1 + SOC 2
Guest payment processing for direct bookings
Data shared: Guest billing email, payment method (PCI-DSS tokenized)
Google LLC
US
SOC 2 Type IIISO 27001
Optional: Gemini AI for analytics insights
Data shared: Anonymized portfolio metrics (no PII)
Security controls

What we actually do

Encryption in transit
Always on
TLS 1.3 enforced on all endpoints. HSTS preloaded with 2-year max-age. No mixed-content possible.
Encryption at rest
AES-256-GCM
AES-256-GCM for all customer secrets (BYO API keys, PMS credentials such as Hostaway, webhook secrets). Database disk encryption via Supabase.
Access control
RBAC
Role-based permissions (owner, operator, admin, viewer) enforced at the route layer. Super-admin bypass requires platform-level credentials and is logged.
Audit logging
Actor-attributed
Write actions (reservation changes, settings updates, member access, platform-setting changes) are logged with actor identity and timestamp.
Backups
Provider-managed
Automated database backups managed by Supabase on dedicated infrastructure. Restore procedure documented in our incident-response runbook.
Secret management
Vault pattern
Customer API keys (BYO Anthropic, PMS/Hostaway credentials) encrypted with AES-256-GCM using a derived key. The platform never logs raw secret values.
Vulnerability management
Recurring audits
Recurring multi-agent security audits of the full codebase (authorization, tenant isolation, injection, cost abuse), with confirmed findings fixed before release. Dependencies updated on a regular cadence.
Incident response
72h disclosure
Documented incident-response runbook covering triage, containment, eradication, and notification. Customer-impacting incidents are disclosed by email without undue delay, at most 72 hours after confirmation.
Data residency & GDPR

Your data, your jurisdiction.

Where your data lives

The primary database is hosted in Tokyo (APAC) and the application runs in Singapore — the regions closest to the villas we serve in Thailand, Bali, Vietnam and surrounding markets. Customer data is not replicated outside that region.

GDPR rights

  • Right to access: request a full data export
  • Right to erasure: account deletion within 30 days
  • Right to portability: JSON + CSV export of all bookings, conversations, properties
  • Right to object: opt out of any non-essential processing
Documents & contact

Resources for your legal team

Data Processing Agreement (DPA)
Standard EU SCCs · GDPR Article 28 compliant · countersigned copy available on request.
Request DPA →Report a vulnerability
Page last reviewed: 2026-08-03 · For changes to sub-processor list, watch this page or email contact@hostellagent.com.