Security & Trust Center

Enterprise Security.
Hospitality Focus.
Built for Trust.

OpeningHub is designed with security, privacy, availability, and operational resilience at its core. We help hospitality organizations manage critical opening, renovation, and operational projects while protecting customer data through layered security controls, continuous monitoring, and documented governance practices.

Monitored continuously by Aikido Security · Reports generated August 2026

Encryption in Transit
Encryption at Rest
Role-Based Access Control
Single Sign-On (SSO)
Multi-Factor Authentication
Audit Logging
Continuous Monitoring
Disaster Recovery
Enterprise IAM
100%
Data Encrypted at Rest
TLS 1.2+
All Connections in Transit
24/7
Continuous Monitoring
4
Framework Alignments
Identity & Access Management

Enterprise Identity & Access Management

OpeningHub is built to integrate with enterprise workforce identity infrastructure. Centralized authentication, granular access controls, and comprehensive audit logging support the requirements of large hospitality organizations and their IT security teams.

ME
Microsoft Entra ID
OK
Okta
GW
Google Workspace
S2
SAML 2.0 Compatible

SAML 2.0 Single Sign-On (SSO)

OpeningHub supports SAML 2.0-based SSO, enabling enterprise customers to integrate OpeningHub directly into their existing identity provider infrastructure. SSO is supported for inbound authentication from Microsoft Entra ID (formerly Azure AD), Okta, Google Workspace, and other SAML 2.0-compatible identity providers.

Multi-Factor Authentication (MFA)

MFA is enforced across all cloud infrastructure access points. Application-layer MFA is available for user accounts, providing an additional authentication barrier against credential-based attacks. MFA enforcement is verified continuously through Aikido Security monitoring.

Role-Based Access Control (RBAC)

OpeningHub implements a multi-tier RBAC model with granular permission scoping at the tenant, project, and record level. Roles are assigned based on least-privilege principles, ensuring users access only the data and functions required for their job function.

Least-Privilege Access Principles

All system roles — internal staff, tenant administrators, external collaborators, and service accounts — are provisioned under a least-privilege model. Access rights are scoped to the minimum necessary for the user's defined function, reducing the blast radius of any potential compromise.

Session Management Controls

User sessions are managed with defined lifetime policies. Session tokens are cryptographically signed, transmitted only over encrypted channels, and invalidated upon logout. Suspicious session activity triggers security alerts.

Authentication Audit Logging

All authentication events — including successful logins, failed attempts, password resets, SSO assertions, and MFA challenges — are recorded in immutable audit logs with timestamps and originating IP addresses.

Administrative Access Controls

Administrative access to the platform infrastructure is restricted to authorized personnel. All administrative actions are logged and reviewed. Access to production systems requires MFA and follows a documented access request process.

Identity Lifecycle Management

User provisioning, de-provisioning, and role changes follow a documented identity lifecycle process. Enterprise customers can integrate with their HR systems or directory services to automate provisioning and ensure timely access revocation.

Application Security

Secure Development & Application Controls

Waypoint Platform Group operates a mature application security program with continuous automated scanning, documented vulnerability management SLAs, and security controls verified by third-party monitoring.

Security risks are continuously evaluated through Aikido Security's real-time monitoring platform. Vulnerabilities are triaged, tracked, and remediated through documented processes aligned with industry-recognized security frameworks.

Implemented

Secure Software Development Lifecycle

  • CI/CD pipeline with automated security gates
  • Dependency lockfiles to pin and verify package versions
  • Connected code repositories with continuous monitoring
  • Secure deployment processes with change tracking
Implemented

Vulnerability Management

  • Continuous dependency scanning via Aikido Security
  • Zero critical or high open-source dependency issues (verified)
  • Documented SLAs for vulnerability remediation
  • No issues outstanding outside of defined SLA thresholds
Implemented

Threat Detection & Malware Prevention

  • Aikido Malware Scanner enabled across infrastructure
  • Real-time threat detection for cloud environments
  • Prevention of unwanted write operations to filesystems
  • Container orchestration takeover protections active
Implemented

Application-Layer Attack Prevention

  • SQL injection prevention verified by Aikido (SOC2 CC6.1)
  • SSRF (Server-Side Request Forgery) protections active
  • XSS (Cross-Site Scripting) prevention enforced
  • Command injection protections implemented
Implemented

Secrets & Configuration Management

  • Application secrets managed through secure secret storage
  • No hardcoded credentials in version-controlled code
  • Environment-based configuration for all sensitive values
  • Up-to-date cryptographic libraries verified continuously
Implemented

Monitoring & Alerting

  • Security event alerting configured and active
  • Cloud environment connected to security monitoring
  • Public-facing domain monitoring enabled
  • Code repository monitoring connected
Implemented

Change Management

  • All changes tracked via issue tracker (ISO A.8.32 compliant)
  • Code repository connected for change detection
  • Authorized deployment processes with approval controls
  • Infrastructure-as-code reviewed for security issues
Implemented

Secure Cryptography

  • SSL/TLS enforced; latest TLS version required
  • Secure cookie configurations enforced
  • Up-to-date cryptographic libraries in use
  • Encryption enforced in transit and at rest
Infrastructure & Hosting Security

Secure Cloud Infrastructure

OpeningHub's hosting environment is engineered for security, availability, and resilience. Infrastructure controls are continuously monitored by Aikido Security, with verified compliance across SOC2, ISO 27001:2022, GDPR, and UK Cyber Essentials frameworks.

Verified

Cloud Hosting & Availability

OpeningHub is hosted on enterprise-grade cloud infrastructure with redundancy, load balancing, and availability protections. Load balancers are configured with secured access points and used correctly to distribute traffic and protect origin services.

Verified

Network Segmentation

Unauthorized public access to file storage and databases is blocked at the infrastructure level. SSH access is restricted. Network configurations are continuously monitored for deviations from secure baselines.

Verified

Access Control for Infrastructure

Cloud resources follow least-privilege access principles. Privileged access to infrastructure is enforced via MFA and restricted to authorized personnel. Deletion protection is enabled for critical cloud resources.

Verified

Backup & Recovery

Automated backups are configured for all stateful cloud resources. Cross-account backups are enabled for disaster recovery scenarios. Backup integrity and completeness are tested to ensure recoverability (SOC2 CC10.3).

Verified

Infrastructure Monitoring

Security logging is enabled on cloud instances. Real-time security alerts are configured. Threat detection is enabled across the environment. Monitoring covers compute, storage, networking, and application layers.

Verified

Domain & DNS Security

DNS domain transfer is locked to prevent unauthorized domain hijacking. Domain monitoring is configured to detect unauthorized changes. Public-facing domain is connected to continuous security monitoring.

Verified

Runtime & Dependency Currency

Cloud instances run on up-to-date runtime versions. Dependency lockfiles pin package versions to verified states. No critical runtime issues are outstanding. Infrastructure-as-code passes automated security checks.

Verified

Capacity & Budget Controls

Cloud capacity and budget alerting is configured to detect anomalous usage patterns. Load balancers are properly configured for capacity management. These controls support both operational stability and early detection of resource abuse.

Infrastructure Security Attestation

The infrastructure security controls listed above are verified through real-time automated scanning by Aikido Security. The verification scope covers cloud access configuration, network policies, encryption enforcement, backup integrity, runtime currency, and threat detection status. Attestation reports are available upon request for enterprise security reviews.

Data Protection

Data Protection & Privacy

OpeningHub processes operational project data on behalf of hospitality customers. We do not process guest personal data, payment card information, or regulated health information. Customer data ownership remains with the customer at all times.

TLS 1.2+ minimum

Encryption in Transit

All data transmitted between clients and OpeningHub infrastructure is encrypted using TLS 1.2 or higher. SSL/TLS enforcement is verified continuously. Secure cookie configurations are enforced. Older, insecure protocol versions are explicitly disabled.

AES-256

Encryption at Rest

All data stored within OpeningHub infrastructure is encrypted at rest. Encryption is enforced at the storage layer using industry-standard algorithms. File storage, databases, and backups are all subject to encryption-at-rest requirements.

You own your data

Customer Data Ownership

Customers retain full ownership of all data they input into OpeningHub. Waypoint Platform Group does not sell, share, or use customer data for purposes other than delivering the contracted services. Customer data is not used for model training, analytics, or product development without explicit consent.

Multi-tenant isolation

Tenant Data Isolation

OpeningHub enforces strict tenant-level data isolation through Row-Level Security (RLS) policies and server-side access enforcement. Tenant data is logically separated at the data layer, preventing cross-tenant data access. All data operations include server-side tenant scope validation.

Defined retention policies

Data Retention Practices

Data retention periods are defined in customer agreements. Upon contract termination, customer data can be exported by the customer prior to deletion. Waypoint Platform Group maintains documented retention and deletion timelines aligned with contractual obligations.

Cross-account backups

Backup Protection

Backups of all stateful data are taken automatically and stored with cross-account separation to protect against infrastructure-level incidents. Backup data is encrypted and access-controlled. Backup integrity is regularly verified.

Documented disposal process

Secure Data Disposal

When customer data reaches the end of its retention period or a contract is terminated, data is securely disposed of following documented deletion procedures. Secure deletion practices apply to all storage tiers.

GDPR-aligned architecture

Privacy by Design

OpeningHub is architected with privacy-by-design principles. Data minimization is applied in data collection practices. Access controls enforce that users can only access data necessary for their role. GDPR Article 4.2 (Data Protection by Design) controls are verified by Aikido Security.

Data Scope Classification

What OpeningHub processes and stores on behalf of customers

Data CategoryExamplesClassificationStatus
Project Management DataOpening timelines, milestones, task assignments, critical path dataOperational Processed & Encrypted
User Identity DataName, email, role, tenant associationPersonal Data Processed & Encrypted
Communication DataProject notes, comments, @mentionsOperational Processed & Encrypted
Document & File DataUploaded project documents, media assetsOperational Processed & Encrypted
Audit & Activity LogsLogin events, data access logs, change historySecurity Processed & Encrypted
Guest PII / Payment DataGuest personal data, credit card dataNot Processed
Not Processed
Regulated Health DataHIPAA-regulated health informationNot Processed
Not Processed
Security Operations & Governance

Formal Security Program

Waypoint Platform Group operates a formal, structured security program — not just technical controls. Our governance framework addresses policies, incident management, vendor oversight, access reviews, and operational resilience planning, ensuring enterprise customers can rely on OpeningHub for critical hospitality operations.

Security Policies & Procedures

Active

Waypoint Platform Group maintains a documented set of security policies governing acceptable use, access control, data handling, incident response, and change management. Policies are reviewed and updated as the security program matures.

Incident Response Program

Active

A documented Incident Response Program defines procedures for detecting, classifying, containing, eradicating, and recovering from security incidents. The program includes defined roles, escalation paths, notification timelines, and post-incident review processes.

Change Management Program

Active

All changes to production systems follow a documented change management process tracked via an issue management system. Change history is maintained for audit purposes. Infrastructure-as-code changes are reviewed for security implications prior to deployment.

Vendor Risk Management

Active

Third-party vendors and subprocessors are evaluated for security posture before onboarding. The vendor risk management program includes ongoing review of critical vendors, contractual data processing agreements, and subprocessor transparency disclosures.

Internal Access Reviews

Active

Access rights to production systems and customer data are subject to periodic internal review. Accounts are audited for necessity, appropriateness, and alignment with current job functions. Unused or excessive access is revoked through the review process.

Security Awareness Practices

Active

Personnel with access to production systems and customer data participate in security awareness practices covering phishing, secure coding principles, data handling, and incident reporting obligations.

Business Continuity Planning

Active

OpeningHub maintains a Business Continuity Plan (BCP) addressing scenarios that could disrupt platform availability. The BCP covers critical process identification, recovery objectives, and communication protocols during disruptions.

Disaster Recovery Planning

Active

A Disaster Recovery Plan (DRP) defines procedures for restoring platform operations following infrastructure-level failures. Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) are defined and reviewed as part of ongoing DR planning.

Security Contact

For security disclosures, incident reports, or questions about our security program, contact the Waypoint Platform Group security team directly. We are committed to timely, transparent responses.

security@waypointplatformgroup.com
Compliance & Assurance

Compliance Program & Roadmap

Important Note: Waypoint Platform Group maintains a security and compliance program designed to align with widely recognized industry frameworks and enterprise customer requirements. The initiatives below reflect current program status accurately. Formal certifications are in active pursuit and are noted accordingly — we do not overstate our certification status.

Current Security Program Areas

Active programs currently operating within the Waypoint Platform Group security organization.

Security Governance
Documented policies, procedures, and accountability structures
Vulnerability Management
Continuous scanning, SLA-based remediation, third-party verification
Access Control Management
RBAC, least-privilege, MFA enforcement, access reviews
Incident Response
Documented IR program with defined roles and notification procedures
Vendor Management
Third-party risk assessment and subprocessor transparency
Business Continuity Planning
BCP and DRP with defined recovery objectives
SOC 2 Type I
In Pursuit

Waypoint Platform Group is actively pursuing SOC 2 Type I attestation. Current security controls align with SOC 2 Common Criteria, verified through Aikido Security continuous monitoring.

65%
Program maturity progress
SOC 2 Type II
Planned

SOC 2 Type II (operational effectiveness over time) is planned following successful Type I attestation. The observation period and audit are being planned for the coming year.

30%
Program maturity progress
ISO 27001:2022
Evaluation

ISO 27001:2022 certification is under evaluation. Current controls have been assessed by Aikido Security against ISO 27001:2022 requirements with strong alignment across access control, cryptography, backup, logging, and vulnerability management domains.

45%
Program maturity progress
GDPR Alignment
Controls Active

GDPR-relevant technical controls — encryption at rest, MFA enforcement, access management, logging, and threat detection — are active and verified. Data Processing Addendum (DPA) is available upon request.

80%
Program maturity progress
UK Cyber Essentials
Controls Active

All five UK Cyber Essentials control categories — network boundaries, secure configuration, user access control, malware protection, and patch management — are verified as active by Aikido Security.

85%
Program maturity progress
Third-Party Audit Evidence

Aikido Security Audit Reports

These reports are generated by Aikido Security based on real-time, automated monitoring of Waypoint Platform Group's code repositories, cloud infrastructure, and public-facing services. They provide independent, continuous verification of security control implementation.

SOC 2
Aikido Security Audit Report · August 2026
View Report

Verified SOC 2 control measures across fraud prevention, risk management, logical access controls, network segmentation, encryption, monitoring, and backup integrity.

CC3.3 — Fraud prevention: Least privilege, MFA, threat detection
CC6.1 — Logical access: MFA, encryption, SQL injection prevention, XSS prevention
CC6.1 — Network segmentation: No public access to storage or databases
CC6.7 — Latest TLS version enforced
CC6.8 — Malware: Aikido Malware Scanner active
CC7.1 — Infrastructure monitoring: Logging, alerting, SLAs configured
CC10.3 — Backup integrity tested
Verified by Aikido Security · Real-time monitoring
ISO 27001:2022
Aikido Security Audit Report · August 2026
View Report

Verified ISO 27001:2022 Annex A control alignment across privileged access, information access restriction, authentication, capacity management, malware protection, vulnerability management, data leakage prevention, backup, and logging.

A.8.2 — Privileged access rights enforced
A.8.3 — Information access restriction: No public cloud exposure
A.8.5 — Secure authentication: MFA, TLS enforced
A.8.8 — Technical vulnerability management: No issues outside SLA
A.8.12 — Data leakage prevention: SSRF, SQL injection, XSS protection
A.8.13 — Backups: Cross-account backups enabled
A.5.15 / A.5.16 — Access control & identity: Least privilege applied
A.5.33 — Protection of records: Encryption at rest
Verified by Aikido Security · Real-time monitoring
GDPR
Aikido Security Audit Report · August 2026
View Report

Verified GDPR technical control alignment covering principles of data processing, data protection by design, processor obligations, records of processing activities, and security of processing.

Art. 2.1 — Encryption at rest, SSL/TLS, secure cookies, up-to-date runtimes
Art. 4.2 — Data protection by design: MFA, proper access management
Art. 4.5 — Processor obligations: Encryption, cryptography, runtime currency
Art. 4.7 — Records of processing: Logging, threat detection, backups enabled
Art. 4.9 — Security of processing: Full encryption stack verified
Verified by Aikido Security · Real-time monitoring
UK Cyber Essentials
Aikido Security Audit Report · August 2026
View Report

Verified against all five UK Cyber Essentials control categories covering boundary firewalls, secure configuration, user access control, malware protection, and patch management.

1.1 — Network boundary: No public access to storage or databases
2.1 — Secure configuration: MFA, encryption, SSL/TLS, secure cookies
3.1 — User access control: MFA, least privilege, threat detection
4.1 — Malware protection: No malware issues, Aikido scanner, CI integration
5.1 — Patch management: All issues within SLA, runtimes up to date
Verified by Aikido Security · Real-time monitoring
Vendor Security Reviews

Supporting Customer Security Reviews

Enterprise procurement, legal, and IT security teams have specific due diligence requirements. OpeningHub actively supports customer security reviews and is committed to providing the documentation and engagement needed for your organization's vendor approval process.

Security Questionnaires

We respond to standard and custom security questionnaires including SIG, CAIQ, VSAQ, and enterprise-specific formats. Our security team completes questionnaires in a timely manner with accurate, auditable responses.

Vendor Risk Assessments

OpeningHub supports formal vendor risk assessments initiated by your procurement or IT security teams. We provide documentation, facilitate conversations with our security team, and can accommodate structured assessment frameworks.

Security Due Diligence Reviews

For enterprise and institutional customers, we support comprehensive security due diligence reviews including documentation requests, security architecture discussions, and review of our security controls program.

Compliance Documentation Requests

We provide available compliance documentation including security reports, data processing addenda, subprocessor lists, incident response overviews, and business continuity summaries upon request.

Direct Security Contact
security@waypointplatformgroup.com

For urgent security inquiries, contact our security team directly. Standard review requests: use the form.

Request a Security Review

We respond to all security review requests within 2 business days.

Subprocessors

Subprocessor Transparency

Waypoint Platform Group maintains transparency about the third-party processors we engage to deliver OpeningHub. Customers are notified of material subprocessor changes with appropriate notice periods.

Last updated
August 2026
ProviderService CategoryPurposeData ProcessedLocationStatus
Base44 (Wix)Platform InfrastructureApplication hosting, backend services, managed database, authentication, and file storageAll application data including user data, project data, and uploaded filesUnited StatesActive
Amazon Web Services (AWS)Cloud InfrastructureObject storage (S3), compute services, and secure media deliveryUploaded documents, media assets, and file dataUnited StatesActive
ResendEmail DeliveryTransactional email delivery for notifications, invitations, and system communicationsEmail addresses, notification contentUnited StatesActive
Aikido SecuritySecurity MonitoringContinuous security scanning, vulnerability management, compliance monitoring, and threat detectionCode repositories, infrastructure configuration metadata (no customer data)Belgium / EUActive
OpenAI / Anthropic / Google AIAI / Language Model ServicesAI-assisted project management features, natural language processing for Pathfinder AI assistantProject context data as provided by users in AI interactionsUnited StatesActive

This subprocessor list reflects services currently engaged by Waypoint Platform Group for OpeningHub. Material changes to subprocessors are communicated to customers with reasonable advance notice. For questions about subprocessor arrangements, contact privacy@waypointplatformgroup.com.

Trust Documents

Security Documentation

The following documents are available to enterprise customers and their security, legal, and procurement teams. Documents marked as "Available on Request" can be obtained by submitting a security review request.

Security Audit Report — SOC 2

Download

Aikido Security continuous monitoring report verifying SOC 2 Common Criteria control alignment across access controls, encryption, monitoring, and backup integrity.

Third-Party ReportAugust 2026

Security Audit Report — ISO 27001:2022

Download

Aikido Security report verifying ISO 27001:2022 Annex A technical control implementation including access control, cryptography, vulnerability management, and logging.

Third-Party ReportAugust 2026

Security Audit Report — GDPR

Download

Aikido Security report verifying GDPR-relevant technical control alignment including encryption, MFA, access management, logging, and data protection by design.

Third-Party ReportAugust 2026

Security Audit Report — UK Cyber Essentials

Download

Aikido Security report verifying UK Cyber Essentials control alignment across network boundary, secure configuration, user access control, malware protection, and patch management.

Third-Party ReportAugust 2026

Vanta Trust Center

Open

Live compliance portal powered by Vanta. View our real-time security and compliance posture, active certifications, and request access to compliance documentation.

Compliance PortalLive

Data Processing Addendum (DPA)

Request

Standard Data Processing Addendum governing the processing of personal data on behalf of enterprise customers, including GDPR Article 28 processor obligations.

Legal DocumentAvailable on Request

Subprocessor List

View

Current list of third-party subprocessors engaged by Waypoint Platform Group, including service category, purpose, data processed, and geographic location.

Transparency DocumentAugust 2026

Incident Response Overview

Request

Summary of OpeningHub's Incident Response Program including detection, classification, containment, notification timelines, and post-incident review processes.

Security DocumentAvailable on RequestRequest Required

Business Continuity & Disaster Recovery Overview

Request

Summary documentation of Business Continuity and Disaster Recovery programs including recovery objectives, tested backup processes, and resilience architecture.

Security DocumentAvailable on RequestRequest Required
Compliance Portal

Trust Center & Compliance

Explore our live compliance status, certifications, and security documentation through our Vanta-powered Trust Center. We are actively pursuing SOC 2 Type II and additional industry certifications as part of our commitment to enterprise-grade security.

trust.waypointplatformgroup.com
Live

Waypoint Platform Group Trust Center

Access our real-time security and compliance posture, active certifications, subprocessor list, and request compliance documentation directly through our Vanta-powered portal.

SOC 2 Type II
In Progress
ISO 27001
Aligned
GDPR
Aligned
Continuous Monitoring
Live
Open Trust Center

Opens in a new tab · Powered by Vanta

Security FAQ

Frequently Asked Security Questions

Answers for procurement, legal, IT security, and compliance teams evaluating OpeningHub for enterprise hospitality deployments.

Contact & Request Access

Request security documentation, report a security concern, or reach our security, privacy, or legal teams.

Security
security@waypointplatformgroup.com

Security questions, concerns, or incident reports

Privacy
privacy@waypointplatformgroup.com

Data privacy and data protection inquiries

Legal
legal@waypointplatformgroup.com

Legal, contracts, and DPA requests

Report a Security Concern

Email security@waypointplatformgroup.com with details. For urgent incidents, include “URGENT” in the subject line.