Trust Contract
Decision support for hospitality capital — propose-only, cited. Not a broker, booking engine, or meeting-sourcing marketplace.
How we earn confidence
Encrypt in transit and at rest
TLS everywhere; database and backups encrypted (provider KMS).
Secrets stay out of code
API keys and tokens live in env/vault only — never in git or the browser.
Read-only links first
Connected data starts as scoped, user-authorized, read-only. We don’t scrape your devices.
Propose-only
We recommend deploy / hold / exit / flag / convert with citations. We do not auto-move capital or sign contracts.
Never write bookings
Not a booking engine. Not a meeting-sourcing marketplace. No writes to PMS / CRS / OTA guest systems.
What it is
- Capital Graph · Radars · Chat · Briefs for hotel investors and operators
- Every material number cited — or marked as an estimate
- Humans Approve / Edit / Dismiss — we never auto-execute
What we never do
- Auto-execute capital, debt, or franchise decisions
- Write to PMS / CRS / OTA booking systems
- Sell scraped outreach lists or spam from this product
- Put secrets in the client or the repo
- Pretend chat memory is a substitute for a connected graph
How we handle data
Public seed — still cited+−
CVB stats, filings, and press are treated as public; answers and Briefs still carry source labels.
Linked accounts — read-only defaults+−
When connectors ship: OAuth or user-controlled upload, least-privilege scopes, read-only until you explicitly widen them.
Encryption+−
TLS in transit; encryption at rest on primary store and backups via cloud KMS. We mirror Silvia’s trust model — not proprietary crypto theater.
Access+−
Service roles are least-privilege; human access to production data is gated and logged as controls mature.
Retention / delete+−
Portfolio-private data follows a documented retention path once connectors ship.
Propose-only boundary+−
Model output is decision support. You ship judgment.
Backend trust roadmap
Phase 0 harden live → Phase 1 Clerk auth live → Phase 2 read-only connectors → Phase 3 attestation. Phase 0 practices are what you see on this site today; later phases ship before we claim them in chrome. No SOC2 theater until attested.
Propose-only · citations required · TLS + encryption at rest · read-only links first · never writes bookings