Platform Controls
- Encryption in transit using modern TLS for data exchanged with our platform.
- Encryption at rest applied by the managed cloud and database services we use.
- Role-based access controls and least-privilege defaults for internal access.
- Authentication safeguards and session protections for end-user accounts.
Operational Practices
- Use of reputable cloud and infrastructure providers to host the service.
- Logging and monitoring of platform activity to detect and investigate anomalies.
- Change management and code review practices for production releases.
- Periodic review of dependencies and security advisories.
Shared Responsibility
Security is a shared responsibility. Customers are responsible for safeguarding credentials, managing user access within their accounts, and reviewing the accuracy of data they upload or connect.
Reporting a Vulnerability
Suspected vulnerabilities can be reported to security@restaurantmanager.com. Please provide enough detail to reproduce the issue. We appreciate responsible disclosure.
This document is maintained by RestaurantManager and applies to use of the RestaurantManager™ platform, websites, applications, and related services. For questions, contact legal@restaurantmanager.com.