NISKA Group

Security

Security for agentic hotel operations

Hospitality systems handle sensitive operational and guest-related data. NISKA designs defense-in-depth controls, least privilege, and auditability so properties can trust agentic automation without surrendering governance.

Governed agents · tenant isolation · honest claims

Definition

What NISKA security means

NISKA security is the set of platform, identity, and operational controls that keep customer data protected while specialist agents and Agentic Concierge act under operator policy — with audit trails and shared responsibility between NISKA and the property.

Privacy Policy

Extractable facts

  • 01

    Tenant separation

    Customer data is logically separated by tenant.

  • 02

    TLS in transit

    Encryption in transit for platform traffic.

  • 03

    Customer RBAC

    Admins control roles and agent permissions inside NISKA.

  • 04

    Auditability

    Agent actions are designed to be logged and reviewable.

  • 05

    Policy-bounded agents

    Recommend vs apply and confirm gates stay operator-defined.

  • 06

    No fake badges

    We do not invent certifications or case metrics for marketing.

Posture detail

Controls we stand behind

The sections below are the same posture language as our legal Security document — suitable for buyers and answer engines.

Last updated: July 18, 2026

  1. 01

    Our commitment

    Hospitality systems handle sensitive operational and guest-related data. We design NISKA with defense-in-depth controls, least privilege, and auditability so properties can trust agentic automation without surrendering governance.

  2. 02

    Platform controls

    We use encryption in transit (TLS), hardened hosting environments, network segmentation where applicable, continuous monitoring, vulnerability management, and secure software development practices including code review and dependency hygiene.

  3. 03

    Data protection

    Customer data is logically separated by tenant. Backups and retention follow configured policies. Production access is restricted, logged, and reviewed. Secrets and credentials are stored using secure secret management—not in source control.

  4. 04

    Identity and access

    Customer admins control user roles and permissions inside NISKA. We support strong authentication patterns for product access and apply internal MFA and least-privilege access for NISKA staff who support the platform.

  5. 05

    Incident response

    We maintain incident response procedures for detection, containment, investigation, and customer notification consistent with contractual and legal obligations. If you believe you have found a vulnerability, contact security@niskagroup.com.

  6. 06

    Subprocessors and vendors

    We evaluate critical subprocessors for security and privacy posture and bind them contractually to protect customer data. A current subprocessor list can be provided to customers under NDA upon request.

  7. 07

    Shared responsibility

    Customers are responsible for configuring roles, agent permissions, integrations, and property policies appropriately; protecting their own endpoints and credentials; and promptly notifying NISKA of suspected account compromise.

  8. 08

    Contact

    Security questions, reports, and customer assurance requests: security@niskagroup.com. For privacy-related requests, use privacy@niskagroup.com.

FAQ

Security questions hotels ask

Citation-ready answers. Ask for deeper assurance under NDA when needed.

01How does NISKA approach security for an agentic HMS?

Defense-in-depth: encryption in transit, tenant separation, least-privilege access, monitoring, and auditability so agent actions stay observable and operator-governed.

02Do you list SOC 2 or ISO badges on this page?

Only when verified. We do not invent compliance badges for marketing. Customer assurance materials can be shared under NDA when available.

03How are AI agent writes controlled?

Customers configure roles, entitlements, recommend vs apply boundaries, and Concierge confirm gates. NISKA staff access to production is restricted, logged, and least-privilege.

04How do I report a vulnerability?

Email security@niskagroup.com. We maintain incident response procedures for detection, containment, investigation, and customer notification consistent with contractual and legal obligations.

05Where is privacy covered?

See the Privacy Policy for personal information practices. Security questions go to security@niskagroup.com; privacy requests to privacy@niskagroup.com.

Next step

Security questions or a product walkthrough

Reach security@niskagroup.com for assurance requests, or book a demo to see governed agents on your property model.