Enterprise Security.
Hospitality Focus.
Built for Trust.
OpeningHub is designed with security, privacy, availability, and operational resilience at its core. We help hospitality organizations manage critical opening, renovation, and operational projects while protecting customer data through layered security controls, continuous monitoring, and documented governance practices.
Monitored continuously by Aikido Security · Reports generated August 2026
Enterprise Identity & Access Management
OpeningHub is built to integrate with enterprise workforce identity infrastructure. Centralized authentication, granular access controls, and comprehensive audit logging support the requirements of large hospitality organizations and their IT security teams.
SAML 2.0 Single Sign-On (SSO)
OpeningHub supports SAML 2.0-based SSO, enabling enterprise customers to integrate OpeningHub directly into their existing identity provider infrastructure. SSO is supported for inbound authentication from Microsoft Entra ID (formerly Azure AD), Okta, Google Workspace, and other SAML 2.0-compatible identity providers.
Multi-Factor Authentication (MFA)
MFA is enforced across all cloud infrastructure access points. Application-layer MFA is available for user accounts, providing an additional authentication barrier against credential-based attacks. MFA enforcement is verified continuously through Aikido Security monitoring.
Role-Based Access Control (RBAC)
OpeningHub implements a multi-tier RBAC model with granular permission scoping at the tenant, project, and record level. Roles are assigned based on least-privilege principles, ensuring users access only the data and functions required for their job function.
Least-Privilege Access Principles
All system roles — internal staff, tenant administrators, external collaborators, and service accounts — are provisioned under a least-privilege model. Access rights are scoped to the minimum necessary for the user's defined function, reducing the blast radius of any potential compromise.
Session Management Controls
User sessions are managed with defined lifetime policies. Session tokens are cryptographically signed, transmitted only over encrypted channels, and invalidated upon logout. Suspicious session activity triggers security alerts.
Authentication Audit Logging
All authentication events — including successful logins, failed attempts, password resets, SSO assertions, and MFA challenges — are recorded in immutable audit logs with timestamps and originating IP addresses.
Administrative Access Controls
Administrative access to the platform infrastructure is restricted to authorized personnel. All administrative actions are logged and reviewed. Access to production systems requires MFA and follows a documented access request process.
Identity Lifecycle Management
User provisioning, de-provisioning, and role changes follow a documented identity lifecycle process. Enterprise customers can integrate with their HR systems or directory services to automate provisioning and ensure timely access revocation.
Secure Development & Application Controls
Waypoint Platform Group operates a mature application security program with continuous automated scanning, documented vulnerability management SLAs, and security controls verified by third-party monitoring.
Security risks are continuously evaluated through Aikido Security's real-time monitoring platform. Vulnerabilities are triaged, tracked, and remediated through documented processes aligned with industry-recognized security frameworks.
Secure Software Development Lifecycle
- CI/CD pipeline with automated security gates
- Dependency lockfiles to pin and verify package versions
- Connected code repositories with continuous monitoring
- Secure deployment processes with change tracking
Vulnerability Management
- Continuous dependency scanning via Aikido Security
- Zero critical or high open-source dependency issues (verified)
- Documented SLAs for vulnerability remediation
- No issues outstanding outside of defined SLA thresholds
Threat Detection & Malware Prevention
- Aikido Malware Scanner enabled across infrastructure
- Real-time threat detection for cloud environments
- Prevention of unwanted write operations to filesystems
- Container orchestration takeover protections active
Application-Layer Attack Prevention
- SQL injection prevention verified by Aikido (SOC2 CC6.1)
- SSRF (Server-Side Request Forgery) protections active
- XSS (Cross-Site Scripting) prevention enforced
- Command injection protections implemented
Secrets & Configuration Management
- Application secrets managed through secure secret storage
- No hardcoded credentials in version-controlled code
- Environment-based configuration for all sensitive values
- Up-to-date cryptographic libraries verified continuously
Monitoring & Alerting
- Security event alerting configured and active
- Cloud environment connected to security monitoring
- Public-facing domain monitoring enabled
- Code repository monitoring connected
Change Management
- All changes tracked via issue tracker (ISO A.8.32 compliant)
- Code repository connected for change detection
- Authorized deployment processes with approval controls
- Infrastructure-as-code reviewed for security issues
Secure Cryptography
- SSL/TLS enforced; latest TLS version required
- Secure cookie configurations enforced
- Up-to-date cryptographic libraries in use
- Encryption enforced in transit and at rest
Secure Cloud Infrastructure
OpeningHub's hosting environment is engineered for security, availability, and resilience. Infrastructure controls are continuously monitored by Aikido Security, with verified compliance across SOC2, ISO 27001:2022, GDPR, and UK Cyber Essentials frameworks.
Cloud Hosting & Availability
OpeningHub is hosted on enterprise-grade cloud infrastructure with redundancy, load balancing, and availability protections. Load balancers are configured with secured access points and used correctly to distribute traffic and protect origin services.
Network Segmentation
Unauthorized public access to file storage and databases is blocked at the infrastructure level. SSH access is restricted. Network configurations are continuously monitored for deviations from secure baselines.
Access Control for Infrastructure
Cloud resources follow least-privilege access principles. Privileged access to infrastructure is enforced via MFA and restricted to authorized personnel. Deletion protection is enabled for critical cloud resources.
Backup & Recovery
Automated backups are configured for all stateful cloud resources. Cross-account backups are enabled for disaster recovery scenarios. Backup integrity and completeness are tested to ensure recoverability (SOC2 CC10.3).
Infrastructure Monitoring
Security logging is enabled on cloud instances. Real-time security alerts are configured. Threat detection is enabled across the environment. Monitoring covers compute, storage, networking, and application layers.
Domain & DNS Security
DNS domain transfer is locked to prevent unauthorized domain hijacking. Domain monitoring is configured to detect unauthorized changes. Public-facing domain is connected to continuous security monitoring.
Runtime & Dependency Currency
Cloud instances run on up-to-date runtime versions. Dependency lockfiles pin package versions to verified states. No critical runtime issues are outstanding. Infrastructure-as-code passes automated security checks.
Capacity & Budget Controls
Cloud capacity and budget alerting is configured to detect anomalous usage patterns. Load balancers are properly configured for capacity management. These controls support both operational stability and early detection of resource abuse.
Infrastructure Security Attestation
The infrastructure security controls listed above are verified through real-time automated scanning by Aikido Security. The verification scope covers cloud access configuration, network policies, encryption enforcement, backup integrity, runtime currency, and threat detection status. Attestation reports are available upon request for enterprise security reviews.
Data Protection & Privacy
OpeningHub processes operational project data on behalf of hospitality customers. We do not process guest personal data, payment card information, or regulated health information. Customer data ownership remains with the customer at all times.
Encryption in Transit
All data transmitted between clients and OpeningHub infrastructure is encrypted using TLS 1.2 or higher. SSL/TLS enforcement is verified continuously. Secure cookie configurations are enforced. Older, insecure protocol versions are explicitly disabled.
Encryption at Rest
All data stored within OpeningHub infrastructure is encrypted at rest. Encryption is enforced at the storage layer using industry-standard algorithms. File storage, databases, and backups are all subject to encryption-at-rest requirements.
Customer Data Ownership
Customers retain full ownership of all data they input into OpeningHub. Waypoint Platform Group does not sell, share, or use customer data for purposes other than delivering the contracted services. Customer data is not used for model training, analytics, or product development without explicit consent.
Tenant Data Isolation
OpeningHub enforces strict tenant-level data isolation through Row-Level Security (RLS) policies and server-side access enforcement. Tenant data is logically separated at the data layer, preventing cross-tenant data access. All data operations include server-side tenant scope validation.
Data Retention Practices
Data retention periods are defined in customer agreements. Upon contract termination, customer data can be exported by the customer prior to deletion. Waypoint Platform Group maintains documented retention and deletion timelines aligned with contractual obligations.
Backup Protection
Backups of all stateful data are taken automatically and stored with cross-account separation to protect against infrastructure-level incidents. Backup data is encrypted and access-controlled. Backup integrity is regularly verified.
Secure Data Disposal
When customer data reaches the end of its retention period or a contract is terminated, data is securely disposed of following documented deletion procedures. Secure deletion practices apply to all storage tiers.
Privacy by Design
OpeningHub is architected with privacy-by-design principles. Data minimization is applied in data collection practices. Access controls enforce that users can only access data necessary for their role. GDPR Article 4.2 (Data Protection by Design) controls are verified by Aikido Security.
Data Scope Classification
What OpeningHub processes and stores on behalf of customers
| Data Category | Examples | Classification | Status |
|---|---|---|---|
| Project Management Data | Opening timelines, milestones, task assignments, critical path data | Operational | Processed & Encrypted |
| User Identity Data | Name, email, role, tenant association | Personal Data | Processed & Encrypted |
| Communication Data | Project notes, comments, @mentions | Operational | Processed & Encrypted |
| Document & File Data | Uploaded project documents, media assets | Operational | Processed & Encrypted |
| Audit & Activity Logs | Login events, data access logs, change history | Security | Processed & Encrypted |
| Guest PII / Payment Data | Guest personal data, credit card data | Not Processed | Not Processed |
| Regulated Health Data | HIPAA-regulated health information | Not Processed | Not Processed |
Formal Security Program
Waypoint Platform Group operates a formal, structured security program — not just technical controls. Our governance framework addresses policies, incident management, vendor oversight, access reviews, and operational resilience planning, ensuring enterprise customers can rely on OpeningHub for critical hospitality operations.
Security Policies & Procedures
ActiveWaypoint Platform Group maintains a documented set of security policies governing acceptable use, access control, data handling, incident response, and change management. Policies are reviewed and updated as the security program matures.
Incident Response Program
ActiveA documented Incident Response Program defines procedures for detecting, classifying, containing, eradicating, and recovering from security incidents. The program includes defined roles, escalation paths, notification timelines, and post-incident review processes.
Change Management Program
ActiveAll changes to production systems follow a documented change management process tracked via an issue management system. Change history is maintained for audit purposes. Infrastructure-as-code changes are reviewed for security implications prior to deployment.
Vendor Risk Management
ActiveThird-party vendors and subprocessors are evaluated for security posture before onboarding. The vendor risk management program includes ongoing review of critical vendors, contractual data processing agreements, and subprocessor transparency disclosures.
Internal Access Reviews
ActiveAccess rights to production systems and customer data are subject to periodic internal review. Accounts are audited for necessity, appropriateness, and alignment with current job functions. Unused or excessive access is revoked through the review process.
Security Awareness Practices
ActivePersonnel with access to production systems and customer data participate in security awareness practices covering phishing, secure coding principles, data handling, and incident reporting obligations.
Business Continuity Planning
ActiveOpeningHub maintains a Business Continuity Plan (BCP) addressing scenarios that could disrupt platform availability. The BCP covers critical process identification, recovery objectives, and communication protocols during disruptions.
Disaster Recovery Planning
ActiveA Disaster Recovery Plan (DRP) defines procedures for restoring platform operations following infrastructure-level failures. Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) are defined and reviewed as part of ongoing DR planning.
Security Contact
For security disclosures, incident reports, or questions about our security program, contact the Waypoint Platform Group security team directly. We are committed to timely, transparent responses.
Compliance Program & Roadmap
Important Note: Waypoint Platform Group maintains a security and compliance program designed to align with widely recognized industry frameworks and enterprise customer requirements. The initiatives below reflect current program status accurately. Formal certifications are in active pursuit and are noted accordingly — we do not overstate our certification status.
Current Security Program Areas
Active programs currently operating within the Waypoint Platform Group security organization.
Waypoint Platform Group is actively pursuing SOC 2 Type I attestation. Current security controls align with SOC 2 Common Criteria, verified through Aikido Security continuous monitoring.
SOC 2 Type II (operational effectiveness over time) is planned following successful Type I attestation. The observation period and audit are being planned for the coming year.
ISO 27001:2022 certification is under evaluation. Current controls have been assessed by Aikido Security against ISO 27001:2022 requirements with strong alignment across access control, cryptography, backup, logging, and vulnerability management domains.
GDPR-relevant technical controls — encryption at rest, MFA enforcement, access management, logging, and threat detection — are active and verified. Data Processing Addendum (DPA) is available upon request.
All five UK Cyber Essentials control categories — network boundaries, secure configuration, user access control, malware protection, and patch management — are verified as active by Aikido Security.
Aikido Security Audit Reports
These reports are generated by Aikido Security based on real-time, automated monitoring of Waypoint Platform Group's code repositories, cloud infrastructure, and public-facing services. They provide independent, continuous verification of security control implementation.
Verified SOC 2 control measures across fraud prevention, risk management, logical access controls, network segmentation, encryption, monitoring, and backup integrity.
Verified ISO 27001:2022 Annex A control alignment across privileged access, information access restriction, authentication, capacity management, malware protection, vulnerability management, data leakage prevention, backup, and logging.
Verified GDPR technical control alignment covering principles of data processing, data protection by design, processor obligations, records of processing activities, and security of processing.
Verified against all five UK Cyber Essentials control categories covering boundary firewalls, secure configuration, user access control, malware protection, and patch management.
Supporting Customer Security Reviews
Enterprise procurement, legal, and IT security teams have specific due diligence requirements. OpeningHub actively supports customer security reviews and is committed to providing the documentation and engagement needed for your organization's vendor approval process.
Security Questionnaires
We respond to standard and custom security questionnaires including SIG, CAIQ, VSAQ, and enterprise-specific formats. Our security team completes questionnaires in a timely manner with accurate, auditable responses.
Vendor Risk Assessments
OpeningHub supports formal vendor risk assessments initiated by your procurement or IT security teams. We provide documentation, facilitate conversations with our security team, and can accommodate structured assessment frameworks.
Security Due Diligence Reviews
For enterprise and institutional customers, we support comprehensive security due diligence reviews including documentation requests, security architecture discussions, and review of our security controls program.
Compliance Documentation Requests
We provide available compliance documentation including security reports, data processing addenda, subprocessor lists, incident response overviews, and business continuity summaries upon request.
For urgent security inquiries, contact our security team directly. Standard review requests: use the form.
Request a Security Review
Subprocessor Transparency
Waypoint Platform Group maintains transparency about the third-party processors we engage to deliver OpeningHub. Customers are notified of material subprocessor changes with appropriate notice periods.
| Provider | Service Category | Purpose | Data Processed | Location | Status |
|---|---|---|---|---|---|
| Base44 (Wix) | Platform Infrastructure | Application hosting, backend services, managed database, authentication, and file storage | All application data including user data, project data, and uploaded files | United States | Active |
| Amazon Web Services (AWS) | Cloud Infrastructure | Object storage (S3), compute services, and secure media delivery | Uploaded documents, media assets, and file data | United States | Active |
| Resend | Email Delivery | Transactional email delivery for notifications, invitations, and system communications | Email addresses, notification content | United States | Active |
| Aikido Security | Security Monitoring | Continuous security scanning, vulnerability management, compliance monitoring, and threat detection | Code repositories, infrastructure configuration metadata (no customer data) | Belgium / EU | Active |
| OpenAI / Anthropic / Google AI | AI / Language Model Services | AI-assisted project management features, natural language processing for Pathfinder AI assistant | Project context data as provided by users in AI interactions | United States | Active |
This subprocessor list reflects services currently engaged by Waypoint Platform Group for OpeningHub. Material changes to subprocessors are communicated to customers with reasonable advance notice. For questions about subprocessor arrangements, contact privacy@waypointplatformgroup.com.
Security Documentation
The following documents are available to enterprise customers and their security, legal, and procurement teams. Documents marked as "Available on Request" can be obtained by submitting a security review request.
Security Audit Report — SOC 2
DownloadAikido Security continuous monitoring report verifying SOC 2 Common Criteria control alignment across access controls, encryption, monitoring, and backup integrity.
Security Audit Report — ISO 27001:2022
DownloadAikido Security report verifying ISO 27001:2022 Annex A technical control implementation including access control, cryptography, vulnerability management, and logging.
Security Audit Report — GDPR
DownloadAikido Security report verifying GDPR-relevant technical control alignment including encryption, MFA, access management, logging, and data protection by design.
Security Audit Report — UK Cyber Essentials
DownloadAikido Security report verifying UK Cyber Essentials control alignment across network boundary, secure configuration, user access control, malware protection, and patch management.
Vanta Trust Center
OpenLive compliance portal powered by Vanta. View our real-time security and compliance posture, active certifications, and request access to compliance documentation.
Data Processing Addendum (DPA)
RequestStandard Data Processing Addendum governing the processing of personal data on behalf of enterprise customers, including GDPR Article 28 processor obligations.
Subprocessor List
ViewCurrent list of third-party subprocessors engaged by Waypoint Platform Group, including service category, purpose, data processed, and geographic location.
Incident Response Overview
RequestSummary of OpeningHub's Incident Response Program including detection, classification, containment, notification timelines, and post-incident review processes.
Business Continuity & Disaster Recovery Overview
RequestSummary documentation of Business Continuity and Disaster Recovery programs including recovery objectives, tested backup processes, and resilience architecture.
Trust Center & Compliance
Explore our live compliance status, certifications, and security documentation through our Vanta-powered Trust Center. We are actively pursuing SOC 2 Type II and additional industry certifications as part of our commitment to enterprise-grade security.
Waypoint Platform Group Trust Center
Access our real-time security and compliance posture, active certifications, subprocessor list, and request compliance documentation directly through our Vanta-powered portal.
Opens in a new tab · Powered by Vanta
Frequently Asked Security Questions
Answers for procurement, legal, IT security, and compliance teams evaluating OpeningHub for enterprise hospitality deployments.
Contact & Request Access
Request security documentation, report a security concern, or reach our security, privacy, or legal teams.
Email security@waypointplatformgroup.com with details. For urgent incidents, include “URGENT” in the subject line.