Encryption
All data encrypted in transit (TLS 1.3) and at rest (AES-256). Guest PII is never exposed in logs or traces.
Security & Compliance
Concya protects guest data with the same standards hospitality venues trust their POS and PMS with. Encryption, role-based access, and a complete audit trail are built into every action the autonomous general manager takes.
Security pillars
Four controls cover the full lifecycle of guest and operational data, from the moment a call is answered to the approval that closes a shift.
All data encrypted in transit (TLS 1.3) and at rest (AES-256). Guest PII is never exposed in logs or traces.
Role-based access with granular permissions. Operators approve every action Concya takes. Service keys are scoped and rotated.
Every action, decision, and approval is logged with timestamp, actor, and context. Full traceability for every shift.
Hosted on Vercel (US-East) with Supabase (AWS). No data leaves your configured region. GDPR-ready with DPA available.
Compliance
Concya is designed for enterprise hospitality buyers. These programs are live or actively in progress, with documentation available on request.
In progress. Controls mapped to the Trust Services Criteria. Audit underway with a licensed assessor.
Available. Data processing records, region pinning, and right-to-erasure support built into the data layer.
Available. Encryption, access logging, and minimum-necessary handling patterns for protected health information.
On request. A signed DPA is available for enterprise and hotel-group customers during onboarding.
Our team can walk you through the architecture, share the DPA, and answer vendor questionnaires for your security review.