Security & Compliance — Aeion Hospitality
Hospitality data is uniquely sensitive: guest names, addresses, payment methods, government ID photos, room access credentials, in-room sensor data. Aeion ships institutional-grade controls across all of it — AES-256-GCM encrypted digital keys with remote revocation, PCI DSS Level 1 via processor passthrough (no card-on-file in Aeion), immutable folio transactions with 12-step night audit, GDPR + CCPA erasure cascade, staff RBAC with separation-of-duties.
Digital Key Security
The highest-risk credential — granting physical access to a room.
Payment Security — PCI DSS Compliance via Passthrough
Aeion never stores cards.
Folio Immutability + Night Audit
Folio transactions are append-only: once posted, a charge can never be edited or deleted — only reversed with a new offsetting transaction, so the trail always stays intact.
Guest PII + GDPR
`
Staff RBAC
Hospitality staff roles map to common job functions.
Compliance Mapping
`
FAQ
Front-desk or GM revokes via admin UI; key status flips to revoked; push to door lock immediately. New key issued same way as original. Audit trail captures.
Configurable per property + jurisdiction. Default: encrypted on-device at check-in; retained 5 years for regulatory; automatically erased after retention period.
Erasure cascades across every connected area — hospitality guest profile, commerce customer record, CRM contact, finance AR record — all anonymized together. Retention-required items (folios for tax, F&B sales for tax) kept but anonymized.
Type 1 in progress; Type 2 in audit cycle for Enterprise. Until formal cert, individual control mappings + auditor letter available.
Bridge sensor integration validates minibar consumption from RFID/weight sensors; folio post auto-generated. Staff cannot manually post minibar charges (segregated permission).
$10M cyber liability via reputable insurer; certificate of insurance available on request.
Annual third-party pentest; quarterly internal red-team. Summary report shared on NDA.
Self-hosted Postgres + S3-compatible storage available via a custom engagement. Air-gapped deployment via custom engagement.
Active; hospitality module vulnerabilities prioritized P1. Submit via /security/bug-bounty.
90-day grace period to export all data; after that, data securely erased per our retention policy. Folio records retained per legal tax-retention requirements (7 years), anonymized for non-active-customer status.