Anana — where AI meets hospitality
HCP — Hospitality Context Protocol
Coming soon
Anana free tools
Free Tools
Purpose-built tools for hospitality.
Research
Research
Original findings on hotel demand and AI discovery.
Blog
Blog
Ideas and analysis for modern hotel commercial teams.
HomeSecurity

Peace of mind for hotel owners, operators, and guests

Hospitality groups across the world trust Anana with their most sensitive guest data. We earn that trust through rigorous security practices, independent audits, and a zero-compromise approach to data protection.

How your data moves

Four stages, each one you control

Connect
Read-only by default

Anana connects to your PMS, CRM, telephony, and messaging through OAuth or scoped service accounts. Write access — a rate change, a sent reply — is granted per integration and per user, and is off until you turn it on.

Process
Encrypted in transit and at rest

TLS 1.2+ everywhere, AES-256 at rest, isolated tenant storage, and secrets held in a managed vault. Model calls run through enterprise agreements with zero-retention terms.

Retain
Your retention, your clock

Set retention windows per source and per property. Transcripts, documents, and derived findings expire on your schedule, and deletion cascades to backups within the documented window.

Audit
Every answer has a trail

Each investigation records the tools called, sources read, and the user who asked. Export the log or stream it to your SIEM.

Questions we get asked
What counts as customer data?

Anything Anana reads or produces on your behalf: guest messages, call transcripts and recordings, reservation and rate data, documents you upload, and the findings Anana writes from them.

Do you train on our data?

No. Inputs, outputs, and uploaded documents are excluded from model training by contract with us and with our model providers.

Where is data hosted?

In the region you choose at onboarding — US or EU — on SOC 2 audited cloud infrastructure, with tenant isolation between customers.

Who at Anana can see our data?

Access is least-privilege, time-boxed, logged, and granted only for support you request. Production access requires approval and MFA.

How do you handle sub-processors?

A current list is published in the Trust Center, with notice before any addition and the right to object under our data processing agreement.

What happens if we leave?

You can export your data and request deletion. Deletion completes within 30 days, backups included, with written confirmation.

Everything above, documented and current