Identity stays bound to the reservation
Guest, room, booking, conversation, Task, Hold, receipt, and Ledger evidence retain one consistent identity.
Trust, without theatre
Renavo is designed to turn guest communication into accountable hotel work. This page separates the controls you can inspect today from the property-specific connections that must be configured and accepted during a pilot.
Updated 19 July 2026
0
success claims without proof
A system write needs a receipt and readback; uncertainty becomes an incident.
1
operation identity per write
Retries recover the same outcome instead of silently repeating the action.
2
first-class product languages
Arabic and English cover the guest and operations experiences.
Guest, room, booking, conversation, Task, Hold, receipt, and Ledger evidence retain one consistent identity.
Property policy decides what may execute. Approval-first mode stages the exact change and waits for a hotel decision.
Supported actions carry an idempotency key, provider receipt, post-write readback, and explicit uncertainty handling.
Owner, manager, and staff permissions are separated. One-time invitations, TOTP MFA, hashed recovery codes, and device-labelled session revocation are built in; pilot readiness stays non-green until privileged staff enroll.
Owner-only export, erasure, retention pruning, and a daily retention worker are part of the product.
Provider timeouts, ambiguous outcomes, delivery failures, and recovery attempts become owned incidents and Ledger events.
Capability boundary
The exact set depends on the deployment. A provider is not treated as a live hotel connection merely because an adapter or account exists.
| Provider | Purpose | Boundary |
|---|---|---|
| Vercel | Application hosting and delivery | Production application traffic and runtime logs |
| Supabase | PostgreSQL authority and realtime | Tenant-scoped operational state and Ledger evidence |
| Google Cloud / Vertex AI | Language-model processing when enabled | Real guest turns only under the configured deployment |
| Cloudflare | Recovery scheduling, monitoring, signed Ledger witnessing, and configured email ingress | Bounded health/recovery calls, append-only Ledger heads, and channel metadata |
| E2B | Disposable computer-use environments | Allow-listed synthetic or explicitly authorized portal workflows |
| Twilio / Meta / LiveKit | SMS, WhatsApp, and voice when commissioned | Disabled until the property channel is configured and accepted |
| Sentry | Error and performance monitoring when enabled | Redacted diagnostics; secrets and unnecessary guest content are excluded |
| Mailjet or configured mail provider | Transactional email and lead notifications | Used only when delivery credentials and sender identity are accepted |
The public showcase is synthetic by design. A pilot starts with one property, one channel, one system path, and explicit acceptance criteria.