Yanolja Cloud Solution · PMS Power Index

Composite score: 34.7 / 100 (published snapshot v2026.2, 2026-06-14)

Yanolja Cloud Solution scores 34.7 out of 100 on the PMS Power Index. Evidence-backed diagnostic across ten API capabilities. Vendor-neutral. Open to dispute.

Scores by capability

Marketplace coverage

Score: 6 of 9 (Adequate). Weight 10%.

First scorer rationale: Clears anchor_6 (at least 6 categories including named examples) via CRM, keyless entry, reputation management, POS, payment gateways and guest messaging. Anchor_9 requires a published certification process which was not found; the 800+ marketplace headline is unverified marketing.

  • At least 6 confirmed integration categories: CRM, keyless entry, reputation management, third-party POS (Oracle, Lightspeed), payment gateways (PCI DSS-certified including eZee Payment Gateway, PayPal, Stripe, regional processors), guest messaging (Twilio, WhatsApp Business API). The 800+ marketplace figure is unverified marketing without a stated certification process; 100–130+ OTAs is channel-manager distribution, not counted toward certified-integration threshold. https://yanoljacloudsolution.com/marketplace

What you can control via the API

Score: 6 of 9 (Adequate). Weight 14%.

First scorer rationale: Adequate (anchor_6). eZee's Connectivity Portal documents a full reservation lifecycle (RES_Request with New / Modify / Cancel), plus two distinct folio-posting endpoints — AddExtraCharge (JSON) and chargepost / "Post Charge To Room" (XML) — with a matching void/delete-charge endpoint. This satisfies anchor_6's compound requirement (reservation lifecycle AND folio posting, both writable). Anchor_9 additionally requires room-move and housekeeping-status endpoints; neither is evidenced in current documentation, so the score lands at anchor_6 rather than anchor_9. Pending secondary review.

  • Room-move and housekeeping-status endpoints are not evidenced in current Connectivity Portal documentation; this prevents the score reaching anchor_9. https://api.ezeetechnosys.com/

Real-time updates and webhooks

Score: 0 of 9 (Absent). Weight 13%.

First scorer rationale: Absent (anchor_0). eZee's "Retrieve all Bookings" documentation explicitly instructs integrators to poll ("We recommend periodically calling the API — every minute, so your system can remain in sync"). No webhook subscription, event catalogue, or payload-signing scheme is documented anywhere in the connectivity API. The single notification-shaped endpoint (BookingRecdNotification) is for partners to confirm receipt to eZee, not for eZee to push events to partners. This is the same anchor_0 finding as Hotelogix's corrected event_driven_capability. Pending secondary review.

  • No webhook subscription, event catalogue, or payload-signing scheme is documented in the eZee connectivity API. The single notification-shaped endpoint (BookingRecdNotification) is for partners to confirm receipt to eZee, not for eZee to push events to partners. https://api.ezeetechnosys.com/

Readiness for AI agents

Score: 3 of 9 (Limited). Weight 12%.

First scorer rationale: Documented REST API meets anchor_3 ("REST API exists and is documented"). No machine-readable schema, no webhooks, no agent primitives. Anchor_6 requires both a published OpenAPI spec and webhook availability; eZee has neither.

  • Connectivity portal documents a REST/XML API with named endpoints, parameter tables, and request/response examples. No OpenAPI or Swagger specification published. No MCP server or agent-callable tool service. No webhook support (per event_driven_capability=0). https://api.ezeetechnosys.com

Data model and multi-property design

Score: 6 of 9 (Adequate). Weight 10%.

First scorer rationale: Matches anchor_6: shared guest profile across properties and multi-property hierarchy in the data model, confirmed via a real client deployment. Anchor_9 requires custom guest-profile attributes and a real-time portfolio-aggregation reporting API; consolidated reporting is described in UI/dashboard terms only, not as API-level aggregation. [Criterion coverage disclosure — 2026-09-21] This dimension's score rests on a single linked evidence row whose source is a site author-archive page on the vendor's documentation domain, and which does not evidence any criterion named at the anchor. No other evidence row is linked to this dimension. The position is disclosed in accordance with the v2.4 criterion-coverage clarification. The published score is unchanged and the dimension is referred to the next scheduled review for re-evidencing.

  • CRS provides single-login access across all properties with centralized guest profile, centralized travel agent profile, and consolidated business insights. Real multi-property deployment confirmed (Capital Hotels, Iceland). https://api.ezeetechnosys.com/author/admin/

Developer tooling and sandbox

Score: 3 of 9 (Limited). Weight 10%.

First scorer rationale: Exceeds anchor_0 via Postman collection and interactive reference but does not reach anchor_6, which requires self-serve sandbox AND at least one official SDK AND an interactive reference AND a published changelog. eZee meets only the Postman/interactive-reference criterion.

  • Sandbox exists but requires registration ("Register here for getting sandbox account"). Downloadable Postman collection confirmed. No official SDK in any language found. No versioned changelog or release notes. https://api.ezeetechnosys.com

Uptime and operational discipline

Score: 0 of 9 (Absent). Weight 9%.

First scorer rationale: Matches anchor_0: no status page, SLA, post-mortems or maintenance announcements found. Unverifiable infrastructure marketing is rejected (parallel to the Hotelogix production_reliability correction in this audit). [Evidence update — 2026-09-21] The statement that no SLA was found is withdrawn. A published service availability commitment of at least 99.95% per calendar month, with a tiered service-credit schedule, is evidenced at points 5 and 6 of the vendor's cloud software terms, a commercial terms page within the evidence scope added by the August 2026 expanded-scope review and not applied to this record at assessment. The findings that no status page, post-mortems or maintenance announcements were located are unchanged. The rejection of the unverified 99.99% infrastructure marketing figure is unchanged and is not relied upon. [Anchor-condition disclosure — 2026-09-21] The conditions stated at the anchors governing this dimension are not established. Anchor 0 requires that no published SLA be present, and that condition is contradicted by the evidence above. Anchor 3 requires a manually updated status page together with the absence of a published SLA, and neither element is established: no status page was located, and a published SLA is present. The dimension therefore falls between anchors as drafted, with no band available for this evidence combination. The published score is unchanged and determination is referred to the next scheduled review.

  • No public status page (automated or manual), no published uptime SLA, no incident post-mortems, no maintenance-window announcements. Only unverifiable marketing language ("heavy-duty, industry standard server and network architecture which ensures maximum uptime"). https://www.ezeeabsolute.com/faqs.php
  • Vendor cloud software terms, point 5: 'Yanolja Cloud Solution shall provide at least 99.95% Service Availability, measured on a per calendar-month basis.' Tiered service-credit schedule at point 6. Commercial terms page, within the evidence scope added by the August 2026 expanded-scope review. https://www.yanoljacloudsolution.com/ycsterms.php

Security, authentication, and compliance

Score: 0 of 9 (Absent). Weight 8%.

First scorer rationale: Matches anchor_0: API key only; no OAuth; no published certifications (SOC2/ISO27001/GDPR DPA); no data processing documentation. PCI DSS is confirmed but is not one of the rubric's named certifications. [Evidence update — 2026-09-21] The statement that no published certifications were found is withdrawn. ISO/IEC 27001:2022, certifying body BSI, and SOC 2 Type II, attesting firm RiskPro, are evidenced from the vendor's own security and compliance page, corroborated by a Yanolja Group announcement of 6 February 2025 naming Yanolja Cloud Solution within the certified scope. Both were publicly available at the date of assessment and were not located, the expanded evidence-search scope covering trust centres and commercial terms pages not having been applied to this record. Under methodology §8b a criterion not located is recorded as such and is not asserted to be absent; the prior wording did not meet that standard and is superseded. The GDPR Data Processing Agreement criterion is recorded as not located. [Anchor-condition disclosure — 2026-09-21] The conditions stated at the anchors governing this dimension are not established. Anchor 0 requires that no published certifications be present, and that condition is contradicted by the evidence above. Anchor 3 requires OAuth 2.0 support together with the absence of published SOC 2 or ISO 27001, and neither element of that condition is established: the vendor's published connectivity documentation specifies basic HTTP authentication with a hotel code and an authentication token, and published certifications are present. The dimension therefore falls between anchors as drafted, with no band available for this evidence combination. The published score is unchanged and determination is referred to the next scheduled review, at which the anchor text is to be redrafted and this record reassessed under the revised text.

  • Yanolja Group announcement, 6 February 2025, of ISO/IEC 27001 and 27701 certification, naming Yanolja Cloud Solution within the certified scope. Predates the 2026-06-14 assessment of this record by sixteen months. https://www.yanoljagroup.com/en/press_release/view?id=1457
  • Connectivity API authenticates via HotelCode and AuthCode credentials with a custom User-Agent header convention (openAPI-{vendorname/propertyname}) — API-key-style, not OAuth 2.0. PCI DSS compliance confirmed, but not among rubric's named certifications (SOC2/ISO27001/GDPR DPA). Published GDPR page is hotel-facing guidance, not a vendor-supplied data processing agreement. https://api.ezeetechnosys.com/category/authentication/
  • Vendor security and compliance page stating ISO/IEC 27001:2022, certifying body BSI, annual audit cycle; and SOC 2 Type II, attesting firm RiskPro. Certificate numbers and audit dates not stated on page. https://yanoljacloudsolution.com/security-and-compliance

Partner programme and references

Score: 3 of 9 (Limited). Weight 7%.

First scorer rationale: Documented partner programme rules out anchor_0. Anchor_6 requires self-serve programme with published tiers, an active developer forum/community, and a publicly searchable directory — eZee meets none of the three.

  • Channel Partner Program documented (dedicated account manager, commission structure, annual maintenance contracts, fulfillment certificate). 38+ resellers worldwide with named testimonials (Boost Hotels Sri Lanka, iP Hoteles Latam). Reseller/distribution focus, not API/integration-developer focus. No developer forum, no published partner tiers with specific economics, no publicly searchable integration-partner directory (Partnerbase.com listing exists but is empty). https://partners.ezeetechnosys.com/benefits.php

Documentation and changelog discipline

Score: 3 of 9 (Limited). Weight 7%.

First scorer rationale: Extensive documentation rules out anchor_0. Anchor_6 requires both versioning AND a published changelog (compound requirement); eZee has neither. Matches anchor_3: documentation exists but is unversioned.

  • Extensive endpoint documentation with named parameters and full request/response JSON/XML examples for reservations, folios, rates, inventory, restrictions and guest data. No version numbers observed in any endpoint documentation. Direct search for eZee changelog or API release notes returned zero eZee-specific results. https://api.ezeetechnosys.com

Scores are published only where documented evidence exists. Corrections and disputes are recorded in the public changelog. The scoring rubric is published in full in the methodology.

This provider is listed in the HotelLogic marketplace →

Rank 14 of 17 scored vendors on the PMS Power Index ladder.