Security Statement

Last updated September 9, 2026

Encryption in transit

Every connection to HostCFO — the dashboard, our APIs, and our booking-platform sync — runs over HTTPS/TLS. Nothing is sent in the clear.

Authentication

Sign-in and account security are handled by a dedicated, industry-standard authentication provider rather than a homegrown password system. We never see or store your booking platform passwords: connections to Airbnb, Vrbo, Booking.com, and other platforms are made through the platform’s own secure sign-in or an API token you can revoke at any time.

Access controls

Your financial and guest data is scoped to your account — other customers can never see it, and internal access is limited to what’s needed to operate and support the product.

Infrastructure

HostCFO runs on established cloud infrastructure providers rather than self-hosted servers, inheriting their physical and network security practices.

Reporting a concern

Found a security issue? We want to know right away — email column.cfo@gmail.com with details and we’ll respond promptly.