Security
How we protect the infrastructure and data behind OHR. This page covers our website and product; see our Privacy Policy for how we handle information.
Last updated: August 12, 2026
Infrastructure security
- All traffic encrypted in transit
- Data encrypted at rest
- Network traffic monitored and filtered for common attack patterns
- Development and production environments fully isolated from each other
Product security
- Authenticated account required for every part of the product
- Invitation-only accounts — no public self-registration
- Product activity logged for audit and troubleshooting
Data & privacy
- Operational data and benchmarking data kept in separate systems
- PMS integrations read only the operational fields needed for benchmarking
- No guest-level personal information collected
- Third-party vendors limited and reviewed for what each can access
Credential & access management
- Credentials and API keys held in a dedicated secrets-management system
- Credentials never committed to source control
- Short-lived, automatically issued deploy credentials — no long-lived keys
- Internal systems run under restricted, least-privilege permissions
- Automated backups with point-in-time restore
Vendor management
We limit the third parties we rely on to deliver our service and review what each one can access. The full list is on our Subprocessors page. For how we collect and use information, see our Privacy Policy.
Reporting a security issue
If you believe you’ve found a security vulnerability in our website or product, email security@ohrreport.com with details and steps to reproduce. We ask that you give us a reasonable opportunity to investigate and address a report before disclosing it publicly.