Choice, visibility, control
Recognition happens when it is appropriate and permitted. Guests can learn what is remembered — and one request removes them across the platform.
Security, privacy, and responsible intelligence are operating requirements — not legal footnotes. This is what the platform is built to do, what it is built never to do, and what is measured rather than promised.
Recognition happens when it is appropriate and permitted. Guests can learn what is remembered — and one request removes them across the platform.
The host remembers what improves hospitality and nothing more. It speaks from curated restaurant knowledge, makes its role clear, and hands difficult moments to people.
Role, brand, and location boundaries decide who can see, change, and act on guest information. Every administrative action is logged and attributable.
Relationships and records are the restaurant’s, always. Tenant data is isolated by architecture — one brand’s guests, menus, and knowledge are never visible to another’s.
Checkout is tokenized through enterprise payment providers in hosted fields. The platform orchestrates the payment; your provider processes it. Payment data stays isolated from conversation and guest data.
The platform remembers preferences, not everything. Nothing is kept without a reason, and erasure on request reaches every corner of the platform.
Enterprise authentication with role-based authorization. Every user, service, and integration operates under least-privilege access; data access is answerable at any time.
Encryption in transit and at rest, secrets in managed stores, development and production fully separated, and every release designed to roll back before it ships.
The host identifies itself as automated, speaks only from curated knowledge — menus, policies, availability — and escalates to a person. Human oversight and continuous evaluation govern what it can say and do.
Deployment choices are documented before production. These are the operating boundaries we confirm with every client.
The restaurant remains owner and controller of its guest relationships and data. Restaurant Companion processes only the configured data needed to provide the service.
Approved restaurant knowledge, guest-provided context, transaction or reservation references, and channel events — limited to categories enabled for the deployment.
Retention is set by data category and client policy during implementation. Approved deletion requests are propagated across the managed deployment.
The cloud, model, communications, payment, and observability providers used by a deployment are documented during diligence. Access is limited and contractually governed.
Regions are selected according to client requirements and provider availability, then confirmed before production.
Defined owners, escalation paths, documentation, and client communication govern response. Privacy inquiries can be sent to privacy@axionari.com.
Client systems remain systems of record. Credentials live in managed secret stores; connector access is least-privilege, scoped, and logged.
PCI-conscious payment architecture. GDPR- and CCPA-aligned data practices. A SOC 2 roadmap with internal governance and security reviews already in motion. We state only the certifications we hold — and architect for the ones that matter next.
Honest today, ready for tomorrow
No certification is implied on this page. When a verified mark is held, it appears here — and nowhere sooner.Measured, not promised
A working session with the platform end-to-end — and straight answers to every question on this page.