ONX Hotel
Guests book. Bots don’t. ONX learns your reservation flow so rooms fill and reception stays with people, not scrapers.
Product
Hotels fill rooms. Municipalities stay reachable. Shops keep selling. ONX decides on your server — and the contract stays in Europe.
Guests book. Bots don’t. ONX learns your reservation flow so rooms fill and reception stays with people, not scrapers.
The official site stays open. Citizens reach services, login and forms — on your server, in the EU, with a DPA legal can sign.
Prices, stock and checkout stay for customers. ONX learns your catalogue, search and cart so shoppers move — automated harvesting does not.
Detection
Most firewalls treat every request the same. ONX sits on your origin and learns the whole site — and already knows what a hotel, a municipality or a shop should look like.
POST /booking/{id}
params: guests, date, notes
methods: POST 98% · GET 2%
notes_max_len: 400
Flagged when notes arrives at 8,492 characters.
How data moves
EU compliance
Protection stays on your server. The picture you need stays in the EU. We write the DPA together — hotels, towns and shops included.
Bots
Google and Bing keep indexing. Scrapers and impersonators stop wasting the pages that sell rooms, services and products.
User-Agent: bingbot/2.0 claimed crawler → reverse + forward DNS IP matches Bing ranges result → pass
Operations
The extras your partner and your team will actually use.
Booking and login stay usable. Scrapers get slowed down so your real traffic keeps the floor.
Hidden traps and proven checks stop the scripts that try to break login, contact and checkout.
See every hotel, town or shop you protect. Fix a mistake in one click. Sleep better.
New protection arrives signed. You say when it goes live. Sites pick it up on their own.
A new hotel, municipality or shop is protected from day one — then ONX learns the details of this site.
Every deployment includes the contract. Public-sector sites get the stricter path. We finish the details with you.
OWASP Top 10 · 2025
ONX maps to the OWASP Top 10. You see the matches first — then you decide how tightly to close the door.
| A01 Broken Access ControlPartial | Forced browsing, path traversal, sensitive file probes, parameter tampering and unusual API shapes. |
|---|---|
| A02 Security MisconfigurationPartial | Exposed config files, hidden paths and suspicious default admin routes. |
| A03 Software Supply Chain FailuresPractice | Client releases are signed and verified on every update. |
| A04 Cryptographic FailuresPractice | ONX does not replace TLS. It helps keep transport headers honest. |
| A05 InjectionCovered | SQL, script, command, file and template injection — including the usual obfuscations. |
| A06 Insecure DesignPractice | Defense in depth. The application’s design remains yours. |
| A07 Authentication FailuresPartial | Slows stuffing and brute force on login and booking. |
| A08 Software or Data Integrity FailuresCovered | Signed core releases, verified before a site accepts them. |
| A09 Security Logging & AlertingCovered | Incidents, an audit trail and a console your operator can read. |
| A10 Exceptional ConditionsPractice | Abnormal request patterns are captured. Safe error pages remain the application’s job. |
We’ll walk through the hotel, the municipality or the shop — and the DPA that goes with it.
Start a conversation