Security & Compliance — Aeion Hospitality

Hospitality data is uniquely sensitive: guest names, addresses, payment methods, government ID photos, room access credentials, in-room sensor data. Aeion ships institutional-grade controls across all of it — AES-256-GCM encrypted digital keys with remote revocation, PCI DSS Level 1 via processor passthrough (no card-on-file in Aeion), immutable folio transactions with 12-step night audit, GDPR + CCPA erasure cascade, staff RBAC with separation-of-duties.

Digital Key Security

The highest-risk credential — granting physical access to a room.

Payment Security — PCI DSS Compliance via Passthrough

Aeion never stores cards.

Folio Immutability + Night Audit

Folio transactions are append-only: once posted, a charge can never be edited or deleted — only reversed with a new offsetting transaction, so the trail always stays intact.

Guest PII + GDPR

`

Staff RBAC

Hospitality staff roles map to common job functions.

Compliance Mapping

`

FAQ

Front-desk or GM revokes via admin UI; key status flips to revoked; push to door lock immediately. New key issued same way as original. Audit trail captures.

Configurable per property + jurisdiction. Default: encrypted on-device at check-in; retained 5 years for regulatory; automatically erased after retention period.

Erasure cascades across every connected area — hospitality guest profile, commerce customer record, CRM contact, finance AR record — all anonymized together. Retention-required items (folios for tax, F&B sales for tax) kept but anonymized.

Type 1 in progress; Type 2 in audit cycle for Enterprise. Until formal cert, individual control mappings + auditor letter available.

Bridge sensor integration validates minibar consumption from RFID/weight sensors; folio post auto-generated. Staff cannot manually post minibar charges (segregated permission).

$10M cyber liability via reputable insurer; certificate of insurance available on request.

Annual third-party pentest; quarterly internal red-team. Summary report shared on NDA.

Self-hosted Postgres + S3-compatible storage available via a custom engagement. Air-gapped deployment via custom engagement.

Active; hospitality module vulnerabilities prioritized P1. Submit via /security/bug-bounty.

90-day grace period to export all data; after that, data securely erased per our retention policy. Folio records retained per legal tax-retention requirements (7 years), anonymized for non-active-customer status.

Hotel security that survives an audit.