Security & integrations
Correct property. Correct permission. Human control.
OMERVIA’s security model is built around property scope, controlled disclosure, event integrity and a deliberate boundary between routine automation and human judgment.
1. Property isolation
Property facts, approved instructions and conversation context are resolved against the exact property. Cross-property errors are treated as a hard safety target of zero. When the system cannot establish the correct scope, the safe behavior is to stop rather than infer a property fact.
2. Protected information
Wi-Fi credentials, access codes and other protected information are not treated as ordinary generic knowledge. Disclosure can depend on the correct reservation and guest-journey phase, and historical guests do not retain indefinite entitlement to operational access information.
3. Event integrity and duplicate control
The implementation uses scoped authentication for internal event paths, timestamps/nonces or equivalent replay protections where configured, stable event deduplication and idempotency controls so a retry or restart does not become an uncontrolled duplicate action.
4. Provider credentials
Provider session credentials are designed to remain inside protected browser/provider contexts rather than being exported into normal workflow payloads or logs. OMERVIA does not ask for a host credential when an authorized integration path does not require it.
5. Human escalation
Automation eligibility is constrained by property context and policy. Refunds, compensation, rule exceptions, serious complaints, legal/safety issues, uncertain protected-information requests and price/contract commitments are escalation cases by default.
6. Integration boundary
OMERVIA is designed to work through authorized provider and channel integrations so operators can keep their existing operational tools. Capabilities shown in conceptual product diagrams represent the operating pattern; they do not by themselves establish an approved partnership, a provider certification or a live production scope.
7. Text-first guest delivery
The current assistant answers using verified text. The property-site URL tool is preserved but disconnected. No image/video is required for onboarding or activation. Any future media capability needs rights, exact-property scope, journey permissions, provider support and separate activation.
Security principle
Identify → Ground → Resolve in text → Govern → Deliver → Learn. Every step remains subordinate to exact-property scope, authorization and the human decision boundary.