Security

Trust starts with clear access, auditability, and controlled handoffs.

SuperNest is built around role-aware access, admin visibility, proof records, responsible data handling, and local QR generation for app handoff flows.

V2 trust

V2 trust copy covers consent, sensitive access, AI audit, compliance, and API governance.

Guest Passport, companions, compliance records, Access Vault, emergency access, documents, exports, and deletion requests require explicit consent and audit.

AI Workbench needs trace IDs, replay controls, prompt/model versioning, guardrails, budget policies, and rollback history.

Developer Platform needs scoped API keys, signed webhooks, replay logs, data export redaction, sandbox controls, and rate limits.

Availability and claim guardrails

Availability, geofencing, and direct booking controls depend on connected calendar, channel manager, payment, and market configuration.

Managed service, AI assistance, revenue recommendations, compliance workflows, partner bookings, and certification remain human-reviewed operational workflows, not guarantees of revenue, legal compliance, provider success, or uninterrupted service.

Auth and role separation

Host, guest, cleaner, companion, superhost, and admin access stay scoped to the right routes and product surfaces.

Admin access controls

The ops console uses explicit admin entry points, demo-mode gating, and operational state boundaries.

Audit-friendly operations

Tasks, proof, incidents, review risk, and AI behavior are presented as reviewable operational records.

Data handling

Stay context, invite attribution, proof metadata, and user roles are designed to preserve the minimum context required for each workflow.

Local QR generation

SuperNest generates app handoff QR codes locally, avoiding dependency on an external QR image provider.

Security contact

Operators can contact SuperNest for security, privacy, and trust questions tied to their hospitality workflows.