Plain-language facts about what's in place today, and what we're still verifying. We only list a control as in place once it has been built and tested.
In placeBeing verified or planned
Restaurant data separation
Every restaurant is its own security tenant. The server checks the restaurant, location and role on every request; IDs sent by a browser are never trusted.
Multi-location access must be granted explicitly per user. Requests for another restaurant's records fail without revealing whether they exist.
Automated tests try to reach one restaurant's data from another and must fail.
Encryption and access controls
All traffic uses HTTPS.
Passwords are hashed with bcrypt. Authenticator secrets and integration credentials are encrypted by the application before storage.
Permissions separate owners, general managers, assistant managers, department managers and employees; employees see only their own information and financial data is limited to owners and GMs.
Encryption at rest for the database, file storage and backups is provided by our hosting platform; we are confirming the exact configuration and will publish it once verified.
Sign-in protection
Two-step verification is required on every plan for owners and anyone with financial or admin access: passkeys/security keys or an authenticator app, with one-time recovery codes. SMS is not offered.
Sign-in and recovery are rate limited; sessions expire after inactivity and can be signed out remotely.
Sensitive actions (exports, security changes, approving support access) require confirming it's you again.
Support access
86'd staff have no standing access to your restaurant's content.
Each support session must be approved by your owner or GM, is time-limited, view-only unless you approve edit access separately, and can be ended by you at any time.
Every support action is recorded in an audit history you can see. We will never ask for your password or verification code.
Payment processing
Subscription payments go through Stripe's hosted checkout, so card details are entered on Stripe's page, not 86'd's servers.
86'd blocks card numbers typed into notes, events or uploads and never sends them to AI.
86'd is not PCI DSS validated; we are completing a scope assessment. Using Stripe reduces, but doesn't remove, PCI responsibilities.
AI data handling
AI features only see data the requesting user is already allowed to see, for the current restaurant and location.
Card numbers and SSN-like patterns are removed before anything is sent. AI never changes records on its own.
Owners can turn off all AI processing. 86'd does not use your data to train shared models.
We are confirming our AI provider's retention and processing-location settings before making further commitments.
Backup and recovery
Your data runs on a managed database operated by our hosting platform.
Backup frequency, encryption, retention and restore testing are being verified with the provider. We don't publish recovery-time or uptime promises until they are tested.
Privacy, retention and deletion
Your restaurant owns its business data. Owners can export everything, request closure, and handle employee or guest data requests from the Legal & Privacy center.
Closed accounts have a 30-day recovery window before permanent deletion; a minimal deletion record is kept.
Our legal documents are drafts pending legal review.
Subprocessors and locations
Emergent (hosting, database, storage, AI gateway), Stripe (payments), OpenAI via the Emergent gateway (AI features, if enabled), Google (optional sign-in), and Toast and OpenTable only if you connect them.
Processing locations are being confirmed with each provider.
Independent assessment status
86'd has not completed a SOC 2 audit, ISO 27001 certification, PCI DSS validation or independent penetration test, and holds no security certifications. We use OWASP ASVS and the NIST Cybersecurity Framework as internal engineering benchmarks. Our hosting providers' certifications cover their own infrastructure, not 86'd.
Report a security issue
Email [Security contact email — pending verification] with details and steps to reproduce. Please don't access other restaurants' data or disrupt the service while testing. 86operations, operated by [Legal entity name — pending verification].