ONEOS

Trust · security, speed & reliability

Built to be trusted with the whole hotel.

ONEOS runs the money, data and daily operations of your hotel, so it’s engineered from the ground up to be secure, fast and dependable. Here’s how.

Uptime
99.9%Commitment, backed by multi-node redundancy and self-healing deployments.
Core reads
<100msHot data paths indexed and tuned, so screens feel instant.
Card numbers held
0Cards go straight to a PCI DSS Level 1 processor. We never see them.
Automated tests
4,000+Every change passes them, plus independent review, before it ships.

01 · Security

Your guests’ data and money, protected by design.

ONEOS protects sensitive data at every layer. It is enforced in the database itself, so a mistake in code can’t quietly expose data.

  • Card numbers never reach us.

    Payments go straight to Stripe. ONEOS only ever holds a token.

  • Each hotel sees only its own data.

    Even inside a group, one property can never see another’s guests.

  • Big refunds need a second person.

    Money actions are limited to the right roles, with four-eyes approval on large refunds.

PCI DSS

Card data never touches our servers.

The simplest PCI scope there is: SAQ-A.

  1. GuestEnters their cardIn an embedded, secure payment form.
  2. card data
  3. Stripe · PCI DSS Level 1Processes the cardThe number goes straight to the processor.
  4. token only
  5. ONEOSRecords the resultA token and the outcome, never the card number.

  • Database-enforced access control

    Sensitive data is protected with row-level security. The application physically cannot read it without passing server-side authentication and authorisation. Every request is authenticated first.

  • Granular, role-based permissions

    A fine-grained capability engine controls who can do what. Refunds, charges and adjustments are gated to authorised roles, with segregation of duties and four-eyes approval on high-value refunds.

  • True multi-tenant isolation

    Every record is scoped to its organisation and property, so one hotel in a group can never see another’s data. That boundary is verified automatically on every code change before it can ship.

  • Built for GDPR and Thailand’s PDPA

    A fail-closed consent ledger, data-access and right-to-erasure workflows and masking of personal data help you meet GDPR and the PDPA. A data processing agreement and our sub-processor list are available on request.

  • Encrypted credentials, no guest passwords

    Third-party credentials sit in an AES-256-GCM encrypted vault. Guests sign in with secure magic links, so there are no guest passwords to steal.

  • Data held in-region

    Your data is hosted in-region (currently Singapore) with encrypted transport (TLS) end to end.

  • AI with guardrails

    Ona works through a controlled tool layer with hard limits and never moves money outside consent-checked paths. Our AI providers are contracted not to train on your data.

  • Continuous security auditing

    An in-house automated QA system runs hundreds of integrity, ledger and security checks across the platform, all the time.

02 · Speed

Engineered for staff who live in it all day.

Front-desk and operations staff make hundreds of interactions per shift. ONEOS is built to feel instant, everywhere.

  • Screens open instantly.

    Even in the check-in rush, pages appear at once and fill in as the data arrives.

  • Reports never slow the desk.

    Heavy reporting runs on its own engine, away from the front desk.

  • Close to your property.

    Served from a global edge network, with your data hosted in Singapore.

  1. EdgeGlobal CDNTLS and DDoS protection, close to every property.Served from the edge
  2. TrafficLoad balancerAutomatic health checks route around any unhealthy node.No single point of failure
  3. ApplicationMultiple app nodesMulti-process serving on every node, scaling out for peak demand.Next.js, sized for click-heavy work
  4. DataOperational databaseIndexed, tuned hot paths. Reporting runs on a separate analytics engine.Core reads under 100ms

  • Global edge delivery

    Served through a global CDN with TLS and DDoS protection at the edge, in front of load-balanced application servers.

  • Scales out for peak demand

    Traffic spreads across multiple application nodes behind a load balancer with automatic health checks, with no single point of failure.

  • Sub-100ms core queries

    Hot data paths are indexed and tuned; the database returns core reads in milliseconds.

  • Pages render immediately

    Screens paint their layout instantly and stream data in, so staff never wait on a blank spinner for a full result set.

  • No wasted work

    Requests are de-duplicated, independent data is fetched in parallel, and no page ever waits on an AI or recommendation call.

  • Analytics that never slow you down

    Heavy reporting runs on a dedicated analytics engine, separate from the live database, so dashboards can’t compete with the front desk.

  • A modern, high-performance stack

    Built on Next.js with multi-process serving on every node, sized for the click-heavy reality of hotel operations.

03 · Reliability

Money that always adds up. A system that stays up.

In a hotel system, “close enough” isn’t good enough, for every charge, every night. ONEOS is built for financial correctness and continuous availability.

  • The bill always adds up.

    Every charge, tax and payment sits in one ledger, exact to the cent.

  • No half-made bookings.

    A booking completes fully or not at all, so a room is never sold twice.

  • Outages don’t lose bookings.

    If a channel goes down, bookings queue and reconcile when it’s back.

  • 99.9%Uptime commitment
  • 1 ledgerEvery charge, payment and refund
  • 4,000+Automated tests on every change
  • 1 → 1,000+Hotels on the same architecture

  • 99.9% uptime commitment

    Backed by multi-node redundancy, load balancing, automatic health checks, self-healing deployments and continuous uptime monitoring.

  • One source of financial truth

    Every charge, tax, payment and refund flows through a single ledger, in exact decimal precision, so totals always reconcile to the cent.

  • All-or-nothing money operations

    Bookings, payments and inventory changes run as atomic transactions. A booking can’t be half-made, or a room double-sold.

  • No single point of failure

    The application runs across multiple load-balanced servers. If a node becomes unhealthy, traffic routes around it.

  • Self-healing deployments

    Every release is health-checked and rolled back automatically if anything fails, so a bad change never reaches guests or staff.

  • Rigorously reviewed code

    Every change passes an independent multi-stage review and 4,000+ automated tests before it ships, with continuous integrity monitoring.

  • Resilient integrations

    Channel and partner connections use a durable retry-and-recovery queue, so a third-party outage is absorbed and reconciled, not lost.

  • Financial period controls

    Business-day close and locking protect settled records from accidental change after the books are closed.

  • From one hotel to a thousand

    The same architecture runs a single boutique property or a chain of 1,000+, and reliability doesn’t degrade as you grow.

Bring your hardest security question.

Walk through how ONEOS protects your guests’ data and money with the people who built it.