Security Statement
Last updated September 9, 2026
Encryption in transit
Every connection to HostCFO — the dashboard, our APIs, and our booking-platform sync — runs over HTTPS/TLS. Nothing is sent in the clear.
Authentication
Sign-in and account security are handled by a dedicated, industry-standard authentication provider rather than a homegrown password system. We never see or store your booking platform passwords: connections to Airbnb, Vrbo, Booking.com, and other platforms are made through the platform’s own secure sign-in or an API token you can revoke at any time.
Access controls
Your financial and guest data is scoped to your account — other customers can never see it, and internal access is limited to what’s needed to operate and support the product.
Infrastructure
HostCFO runs on established cloud infrastructure providers rather than self-hosted servers, inheriting their physical and network security practices.
Reporting a concern
Found a security issue? We want to know right away — email column.cfo@gmail.com with details and we’ll respond promptly.