Security practices

Clear, current security information

These are the controls currently represented in the product. Ask our team about the exact configuration for your deployment.

AES-256-GCM
Sensitive credentials
HTTPS/TLS
Encrypted transport
Role-based access
Admin and branch roles
Restaurant scope
Tenant-aware access
Audit history
Operational visibility
Health monitoring
Service checks and logs

Encrypted secrets

Sensitive provider credentials stored by the platform are protected with AES-256-GCM encryption. Traffic to the service is served over HTTPS.

Access control

Administrative features are restricted by authentication, role, restaurant, and branch scope. Keep user access limited to operational need.

Operational safeguards

Health checks, service logs, delivery histories, and controlled deployment procedures help operators detect and investigate issues.

Accurate assurance

We describe implemented controls and do not present an audit, certification, uptime SLA, or penetration-test programme unless it has been formally completed.

Data minimisation

Only configure the data and external credentials needed for the active workflow. Retention and deletion requests are handled according to operational and legal requirements.

Shared responsibility

Restaurants remain responsible for staff permissions, provider accounts, recording notices, consent, and local legal obligations.

Need technical details for your deployment or procurement review?

Contact the technical team