Security
We would rather explain plainly what is actually true about how this platform is built than list certifications we don’t hold. Here is the real architecture behind your account.
Tenant data isolation
Every business that signs up is its own organization record. Every piece of business data — customers, orders, inventory, staff accounts, drivers, coupons, and more — is scoped to that organization at the database query level. One organization’s staff cannot see another organization’s data through the application.
Authentication
Staff log in with a username and password scoped to their business. Passwords are hashed before storage — we do not store or ever display plain-text passwords. Repeated failed login attempts are throttled to slow down guessing attacks.
Roles & permissions
Staff accounts are assigned roles (such as owner, staff, or driver) that control which parts of the dashboard they can see and act on. A platform administrator role exists separately for our own support and billing tools, and cannot see the contents of your customer data beyond what’s needed to support your account.
Infrastructure
The application runs on managed hosting with a managed PostgreSQL database. We do not run our own physical servers.
What we don’t claim
We are an early-stage platform. We do not currently hold SOC 2, PCI, or HIPAA certification, and we won’t claim an uptime guarantee we haven’t earned. If and when that changes, this page will be updated to reflect it — not before.
Questions
If you have a specific security question before signing up, contact us and we’ll answer it directly.
