Back to Home
Security and trust

Clear controls, honest boundaries.

This page explains how RestoManage currently protects the public website and restaurant platform, what remains the customer’s responsibility, and how to report a security concern.

Last reviewed: August 3, 2026

Report a concern

Email the RestoManage security contact with the subject Security report. Please include the affected product or URL, steps to reproduce, potential impact, and a safe way to contact you.

contact@getrestomanage.com

Do not include live credentials, payment data, or unnecessary personal information in an initial report.

Current controls

Security built into everyday operations

These descriptions explain the protections customers interact with and the responsibilities that remain with each organization.

Offline-first POS design

The desktop POS is designed to keep core local workflows available during temporary connectivity loss and synchronize supported data when connectivity returns. Cloud-dependent actions still require a working connection.

Encrypted connections

Production website and platform traffic is delivered over HTTPS. Connections to managed database, authentication, storage, and email providers use their protected service endpoints.

Scoped access controls

Authenticated product access is limited by organization, branch, terminal, role, and permission checks where those scopes apply. Privileged server credentials are not intended for browser use.

Private supplier documents

Supplier catalogs are kept private and made available through controlled access for authorized review workflows.

Public-form abuse controls

Public forms use anti-abuse controls and field validation to reduce automated submissions and unnecessary data processing.

Controlled software changes

Application changes go through review, regression checks, and production builds before release.

Responsible disclosure

Help us investigate safely

Good-faith reports help us improve. Avoid disrupting live restaurants, accessing data that is not yours, changing records, or using social engineering.

  1. 1

    Send a focused report

    Describe the affected surface, reproduction steps, observed behavior, expected behavior, and likely impact.

  2. 2

    We triage the issue

    We confirm receipt when practical, assess severity, preserve relevant evidence, and identify the affected owner.

  3. 3

    We coordinate remediation

    We may ask for clarification, test a correction, and sequence deployment according to risk and customer impact.

  4. 4

    We confirm the outcome

    When practical, we confirm the result after the issue has been addressed safely.

Current boundaries

  • No internet-connected service can eliminate every risk or promise uninterrupted availability.
  • Offline-first operation covers supported local workflows, not every cloud, email, payment, or third-party action.
  • Private supplier storage and file validation reduce exposure, but uploaded documents must still be treated as untrusted.
  • Third-party providers remain responsible for the security and availability of their own services.

Shared responsibility

RestoManage protects the platform controls it operates. Restaurants and suppliers control their users, devices, networks, submitted data, and the third-party accounts they connect or use alongside the platform.

Security details may change as the product evolves. Material updates will be reflected on this page.

Customer checklist

Keep your side of the door locked

Platform controls work best when restaurants pair them with disciplined account and device management.

  • Use unique accounts and grant only the permissions each team member needs.
  • Protect restaurant devices, operating-system accounts, email inboxes, and recovery channels.
  • Keep supported RestoManage applications and device software updated.
  • Review staff access promptly when roles change or employment ends.
  • Avoid uploading unnecessary secrets or unrelated personal information in free-text fields and supplier files.

Privacy and security belong together

Read how website submissions, supplier documents, operational records, and service providers are described in the RestoManage Privacy Policy.

Read the Privacy Policy
Security and Trust Center | RestoManage