This Security Statement describes the technical and organisational measures Markoni maintains to protect owner, guest and operational data, and the physical security practices applied at managed properties. It is provided for information and does not create contractual commitments except as incorporated into a Management Agreement.
Markoni does not store full payment-card numbers. Payment transactions are processed by booking platforms and payment processors that represent compliance with PCI-DSS; Markoni's systems receive confirmations and settlement records only.
Markoni maintains a documented incident-response process with defined severity levels, escalation paths and post-incident review. Where an incident affects your personal data or your property, Markoni will notify you without undue delay and within the timelines required by applicable law, describing the nature of the incident, the data or assets concerned and the remedial measures taken or proposed.
Security researchers acting in good faith are asked to report suspected vulnerabilities to security@markoni.ai. We acknowledge reports within forty-eight (48) hours, will not pursue legal action in respect of good-faith research conducted without harm to data subjects or systems, and request that findings not be publicly disclosed until remediated.