Security Overview
Public summary of Prehoos security practices
| Term | Meaning |
|---|---|
| Legal Owner | ENTERACT LLC |
| Product | Prehoos |
| Effective date | June 28, 2026 |
1. Overview
ENTERACT LLC designs Prehoos to support secure hospitality operations. This Security Overview summarizes practices used to protect the Platform and Customer Data. It is a public summary, not a complete description of all controls and not a guarantee that incidents cannot occur.
2. Shared responsibility
3. Access controls
- Role-based user access and administrative controls where supported by the Platform.
- Customer-controlled user creation, role assignment, access removal, and permission configuration.
- Internal access restrictions designed to limit Company personnel access to Customer Data to personnel with business need.
- Logging and audit records used to support troubleshooting, security review, and accountability.
4. Data protection
- Encryption in transit using industry-standard protocols where supported.
- Logical controls designed to separate customer accounts and limit unauthorized access.
- Backup and recovery practices appropriate to the hosting environment and subscription plan.
- Retention and deletion practices described in the Terms, Privacy Policy, and DPA.
5. Application security
- Secure development practices appropriate to the product lifecycle.
- Change management and release practices designed to reduce operational risk.
- Error monitoring, logging, and diagnostic review to detect and resolve issues.
- Security review of sensitive features such as authentication, permissions, integrations, payments, APIs, and automation.
6. Infrastructure and subprocessors
Prehoos may use third-party infrastructure, hosting, email, messaging, analytics, support, payment, and security providers. The Subprocessor List identifies vendors that may process Customer Data. Company reviews vendors based on business need, security, privacy, and operational requirements.
7. Incident response
Company maintains processes to identify, investigate, contain, remediate, and communicate relevant security incidents. If Company becomes aware of a Personal Data breach affecting Customer Data, Company will notify affected Customers according to the Data Processing Addendum and applicable law.
8. Customer security recommendations
- Use unique accounts for each staff member; do not share passwords.
- Use strong passwords and multi-factor authentication where available.
- Grant the least access needed for each role.
- Review staff access regularly, especially after role changes or termination.
- Limit administrative privileges to trusted personnel.
- Do not store raw card data, CVV, PINs, or sensitive authentication data in notes or unapproved fields.
- Use trusted devices and secure networks for front desk, accounting, and owner/admin access.
- Review audit logs and financial alerts where available.
9. Vulnerability reporting
Suspected security vulnerabilities should be reported to security@prehoos.com or support@prehoos.com. Do not access, modify, delete, exfiltrate, or disrupt data or systems while investigating a vulnerability. Security testing requires prior written authorization.
10. No absolute guarantee
No internet-based system is completely secure or error-free. This Security Overview does not create warranties beyond those expressly stated in the Terms, SLA, DPA, or signed Order Form.
