Offline-first POS design
The desktop POS is designed to keep core local workflows available during temporary connectivity loss and synchronize supported data when connectivity returns. Cloud-dependent actions still require a working connection.
This page explains how RestoManage currently protects the public website and restaurant platform, what remains the customer’s responsibility, and how to report a security concern.
Last reviewed: August 3, 2026
Report a concern
Email the RestoManage security contact with the subject Security report. Please include the affected product or URL, steps to reproduce, potential impact, and a safe way to contact you.
contact@getrestomanage.comDo not include live credentials, payment data, or unnecessary personal information in an initial report.
Current controls
These descriptions explain the protections customers interact with and the responsibilities that remain with each organization.
The desktop POS is designed to keep core local workflows available during temporary connectivity loss and synchronize supported data when connectivity returns. Cloud-dependent actions still require a working connection.
Production website and platform traffic is delivered over HTTPS. Connections to managed database, authentication, storage, and email providers use their protected service endpoints.
Authenticated product access is limited by organization, branch, terminal, role, and permission checks where those scopes apply. Privileged server credentials are not intended for browser use.
Supplier catalogs are kept private and made available through controlled access for authorized review workflows.
Public forms use anti-abuse controls and field validation to reduce automated submissions and unnecessary data processing.
Application changes go through review, regression checks, and production builds before release.
Responsible disclosure
Good-faith reports help us improve. Avoid disrupting live restaurants, accessing data that is not yours, changing records, or using social engineering.
Describe the affected surface, reproduction steps, observed behavior, expected behavior, and likely impact.
We confirm receipt when practical, assess severity, preserve relevant evidence, and identify the affected owner.
We may ask for clarification, test a correction, and sequence deployment according to risk and customer impact.
When practical, we confirm the result after the issue has been addressed safely.
RestoManage protects the platform controls it operates. Restaurants and suppliers control their users, devices, networks, submitted data, and the third-party accounts they connect or use alongside the platform.
Security details may change as the product evolves. Material updates will be reflected on this page.
Customer checklist
Platform controls work best when restaurants pair them with disciplined account and device management.
Read how website submissions, supplier documents, operational records, and service providers are described in the RestoManage Privacy Policy.