Security

    Security byarchitecture.

    We take a defensive-first approach to hospitality operations. Your venue's data is not just stored. It is isolated, encrypted, and protected at every layer.

    1. 01

      Isolated infrastructure

      OPPI operates on logically isolated cloud architecture with AES-256 encryption at rest and TLS 1.3 in transit.

      Point-in-time recovery enabled

    2. 02

      Identity governance

      Granular role-based access control ensures your venue data is only accessible by authorised personnel.

      Secure session persistence, MFA ready

    3. 03

      Privacy by design

      We treat venue data as a liability, not an asset. Your operational data is never sold or shared with third parties.

      Fully isolated operational environments

    4. 04

      Agentic safety

      Our AI agents operate within strictly defined sandboxes with no cross-organisation knowledge or data leakage.

      Context-aware security boundaries

    Logically isolated.
    Always encrypted.

    01

    Encryption in transit and at rest

    Data is encrypted from the point it reaches our infrastructure using TLS 1.3, and stored with AES-256 encryption at rest.

    02

    Continuous infrastructure monitoring

    Our cloud provider monitors infrastructure health, access patterns, and anomalous activity. We review alerts and audit logs regularly.

    03

    Logical data isolation

    Venue data is logically isolated at the database level. Each customer's data is partitioned so one organisation cannot access another's information.

    04

    Data residency

    Venue data is hosted on enterprise cloud infrastructure in Singapore (AWS ap-southeast-1), encrypted at rest, with point-in-time recovery enabled.

    05

    AI processing, disclosed

    AI tasks are routed to OpenAI, Anthropic (Claude), Google (Gemini) and Perplexity under data processing agreements with each provider. Your data is sent only to answer the task at hand, is never used to train provider models, and trains only your venue's own model.

    06

    Deletion, with a timeframe

    Request deletion and your data is removed in full, backups included, within 30 days. Your operational history belongs to your venue, not to us.

    Data residency

    Our primary database infrastructure is hosted in Singapore (AWS ap-southeast-1). Application hosting and AI processing may utilise servers in additional regions. For full details on where your data lives and cross-border disclosures under Australian Privacy Principle 8, see Section 07 of our Privacy Policy.

    Compliance roadmap

    We are building OPPI to meet industry standards from day one. As we scale, we are actively working toward the following certifications.

    ISO 27001Planned
    SOC 2 Type IIPlanned
    GDPRCompliant
    APPCompliant
    Servance Pty Ltd · oppi.au
    SEC-2026-001

    Need more detail?

    If your venue has specific security requirements or compliance needs, we are happy to discuss them directly.

    Contact the security team