Trust

Security Statement.

Last updated August 7, 2026

This Security Statement describes the technical and organisational measures Markoni maintains to protect owner, guest and operational data, and the physical security practices applied at managed properties. It is provided for information and does not create contractual commitments except as incorporated into a Management Agreement.

1. Information Security

  1. Encryption. Data is encrypted in transit using industry-standard protocols (TLS 1.2 or higher) and at rest.
  2. Access control. Access to systems and data is granted on a least-privilege, role-based basis, is authenticated, is logged, and is reviewed periodically. Access is revoked promptly upon role change or termination.
  3. Credential handling. Credentials and authorisations granted by owners (including channel accounts, calendars and smart-lock systems) are held in a managed secrets vault, are never stored in plain text, and are revoked at off-boarding.
  4. Vendor management. Processors and infrastructure providers are assessed prior to engagement and are bound by written data-processing agreements imposing confidentiality and security obligations.

2. Payment Security

Markoni does not store full payment-card numbers. Payment transactions are processed by booking platforms and payment processors that represent compliance with PCI-DSS; Markoni's systems receive confirmations and settlement records only.

3. Physical Security at Managed Properties

  1. Access by service personnel and vendors is scheduled, scoped to the task and logged.
  2. Where installed hardware permits, smart-lock access codes are rotated on a per-stay basis.

4. Incident Response

Markoni maintains a documented incident-response process with defined severity levels, escalation paths and post-incident review. Where an incident affects your personal data or your property, Markoni will notify you without undue delay and within the timelines required by applicable law, describing the nature of the incident, the data or assets concerned and the remedial measures taken or proposed.

5. Responsible Disclosure

Security researchers acting in good faith are asked to report suspected vulnerabilities to security@markoni.ai. We acknowledge reports within forty-eight (48) hours, will not pursue legal action in respect of good-faith research conducted without harm to data subjects or systems, and request that findings not be publicly disclosed until remediated.