This document is part of ORION’s trust framework for its web platform and future mobile applications, operated by TROYANTECHNOLOGY SAS from Ecuador.
Security commitment
TROYANTECHNOLOGY SAS manages security as an ongoing process covering people, technology and suppliers, with controls proportionate to the sensitivity of hotel and account data.
Identity and access control
ORION uses authenticated accounts, secure password storage, role-based permissions, branch assignments and owner-controlled access. Administrative actions are recorded when appropriate.
Tenant isolation
Business data is scoped by tenant and authorization is enforced server-side. A user linked to multiple companies accesses each workspace independently and only with an active assignment.
Data protection
Transport encryption, secret management, backups, validation and least-privilege practices protect data throughout its lifecycle. Payment credentials are handled by the selected payment provider.
Secure operations
Logging, audit events, dependency maintenance, vulnerability management, recovery procedures and restricted production access support prevention, detection and response.
Incident response
Suspected incidents are assessed, contained, documented and remediated. Affected customers and authorities are notified when required by law or contract.
Report a vulnerability
Send responsible disclosures to security@orion-pms.com with steps to reproduce and impact. Do not access third-party data, disrupt the service or publicly disclose an unresolved issue.