Trust centerAnotherPillow index
Security as a system boundary — not a slogan.
AnotherPillow separates hotels, constrains AI, avoids raw card data and logs changes. Live integrations activate only after verified tests.
Least privilege by defaultHotel data stays separated
Every read and write must be tied to the right hotel and an authorised identity.
- Ownership checks at the data layer
- Private admin surface
- Audit history for account changes
Funds do not pass through our code
Raw card numbers go directly to the hotel’s payment provider. AnotherPillow stores only the required status and reference.
- Stripe-hosted payment fields
- The hotel is the merchant
- Refunds require authorisation
AI has hard boundaries
The assistant can read approved sources and prepare work, but cannot move money, change a rate or contact guests on its own.
- Source-grounded knowledge
- Human approval
- Traceable suggestions
Phone booking never asks for card details
A future AI booking call identifies the assistant, minimises retained call data and moves payment into a secure hosted checkout.
- No card number spoken to AnotherPillow
- Human transfer at any time
- Call disclosure and retention configured per market
Production is a gate, not a label
The public site is a development environment. A real hotel remains blocked until identity, data responsibility, recovery and every selected connection have passed an accountable launch review.
- Hotel roles and access recovery
- Data-processing and subprocessor terms
- Backup restore and incident drill
Trust center · AnotherPillow