The platforms we build handle live order, payment, and staffing data. We apply enterprise-grade security practices to every deployment.
Infrastructure Security
We deploy on established cloud infrastructure providers that maintain SOC 2 Type II and ISO 27001 compliance. All data at rest is encrypted with AES-256, and all data in transit is protected with TLS 1.3.
Application Security
- Authentication: Hardened session management with support for multi-factor authentication on manager and admin accounts.
- Access control: Role-based permissions ensure kitchen staff, front-of-house, and managers can only view records their role is authorized to access.
- Transaction integrity: Order and payment events are logged immutably, so historical records can't be altered after the fact.
- Audit logging: Key actions on voids, comps, and access records are logged for review.
Payment Security
Toasty Coconut does not store credit card numbers on our own servers. All payment processing is handled through PCI-DSS Level 1 certified providers.
Vulnerability Reporting
If you believe you've found a security vulnerability in our systems or in a platform we've deployed for a client, please email security@toastycoconut.us. We respond to all reports within 48 hours.