Security

Hostme processes data of restaurants and their guests. This page summarizes how we protect it.

Where your data lives

  • Hostme services run on Microsoft Azure, United States.
  • Microsoft Azure data centers maintain SOC 1/2/3, ISO 27001 and ISO 27018 attestations — see the Microsoft Azure Trust Center.

How we protect data

  • Encryption in transit: TLS 1.2+ for all client–server connections.
  • Encryption at rest: data stored in Azure services with encryption at rest (AES-256).
  • Access control: role-based access control in the product; least-privilege for staff; multi-factor authentication for administrative access.
  • Payments: card payments handled by Stripe via PCI-compliant link-based flows; Hostme never stores full card numbers.
  • Backups: automated backups with restricted access.
  • Monitoring: centralized security logging and monitoring of production systems.

Compliance

  • GDPR: we maintain a Privacy Policy, offer a Data Processing Addendum (EU SCCs Module Two + UK Addendum) to customers to whom it applies, and publish a Subprocessor list.
  • Hostme does not currently hold its own SOC 2 or ISO 27001 certification. We rely on the underlying Azure compliance program and our internal security measures.
  • Contact for security inquiries: security@hostmeapp.com.

Report a vulnerability

We appreciate responsible disclosure. Please report suspected vulnerabilities to security@hostmeapp.com. We review all reports.