How we protect your data.
Security is built into RosPos AI from the ground up. Here's what's in place.
Encryption in transit
All traffic runs over HTTPS/TLS. Data moving between your browser and our servers is encrypted.
Secure logins
Passwords are hashed (never stored in plain text). Sessions use secure, http-only cookies with CSRF protection.
Two-factor authentication
Owners and staff can enable an authenticator-app code on login, and admins can require 2FA across a team.
Tenant isolation
Every restaurant's data is strictly scoped to that restaurant — one account can never read or change another's data.
Payments
Card payments run through established payment providers. We don't store full card numbers on our servers.
Backups
The database is backed up automatically every night to off-site storage, so your data survives hardware failure.
Monitoring
Errors and downtime are monitored so problems are caught and fixed quickly.
Found a security issue? Please email hello@restroai.live — we take reports seriously.