Security
Hostme processes data of restaurants and their guests. This page summarizes how we protect it.
Where your data lives
- Hostme services run on Microsoft Azure, United States.
- Microsoft Azure data centers maintain SOC 1/2/3, ISO 27001 and ISO 27018 attestations — see the Microsoft Azure Trust Center.
How we protect data
- Encryption in transit: TLS 1.2+ for all client–server connections.
- Encryption at rest: data stored in Azure services with encryption at rest (AES-256).
- Access control: role-based access control in the product; least-privilege for staff; multi-factor authentication for administrative access.
- Payments: card payments handled by Stripe via PCI-compliant link-based flows; Hostme never stores full card numbers.
- Backups: automated backups with restricted access.
- Monitoring: centralized security logging and monitoring of production systems.
Compliance
- GDPR: we maintain a Privacy Policy, offer a Data Processing Addendum (EU SCCs Module Two + UK Addendum) to customers to whom it applies, and publish a Subprocessor list.
- Hostme does not currently hold its own SOC 2 or ISO 27001 certification. We rely on the underlying Azure compliance program and our internal security measures.
- Contact for security inquiries: security@hostmeapp.com.
Report a vulnerability
We appreciate responsible disclosure. Please report suspected vulnerabilities to security@hostmeapp.com. We review all reports.