Security & Compliance
Bank-grade encryption, cryptographic offline leases, and multi-tenant database defense.
All data in transit between browser terminals, handhelds, kitchen screens, and our cloud database is protected using modern TLS 1.3 encryption protocols.
Offline functionality is cryptographically signed with local SHA-256 HMAC tokens, preventing unauthorized clock skewing or license tampering.
Every restaurant's data is isolated with unique tenant bounds and scoped SQL statements, ensuring zero cross-store leakage or unauthorized access.
Role-Based Access Control separates Captains, Cashiers, Kitchen Station Chefs, Managers, and Store Admins with strict PIN and session timeouts.
All POST/PUT API mutations require strict cryptographic anti-CSRF tokens and strict Content-Security-Policy headers to block malicious script injections.
Continuous point-in-time recovery and automated off-site database backups with instant restore capabilities in the event of hardware failures.
Report a Vulnerability
We operate a responsible disclosure policy. If you have discovered a security concern, please contact our dedicated security team immediately.
Contact Security Team