Skip to content
Security

What We Do, and Where the Boundaries Are

A short, checkable account of how Devfood handles your data — and an equally clear account of how far our assurances go.

Read the second half of this page first. Most security pages are a list of reassurances. The part of this one worth your time is the boundaries we state up front — if one of them is a requirement for you, you will find out here rather than three weeks into a procurement review.

Tenant isolation

Every business on the platform is a separate tenant. Menus, orders, customers and staff accounts are scoped to that tenant, and a request carrying one tenant’s credentials cannot read another’s records.

Access control by role

Staff accounts are role-scoped — a counter user, an outlet manager and an owner see different things. Outlet staff are limited to their own outlet’s data rather than the whole group’s.

Card details never touch us

Payments are handled by the processor’s own hosted flows. Card numbers are entered into the processor, not into our apps, and we never store them.

Encryption in transit

Every connection between the apps and the platform is served over HTTPS. This website enforces HSTS and ships a restrictive content-security policy.

Your accounts, your money

Payment accounts belong to you. Settlement runs from the processor to your bank without passing through an account of ours, so a dispute with us is never a dispute about your takings.

Your data is exportable

Customer records, order history and reporting can be exported from the admin dashboard. Data portability is a product feature rather than a favour, because leaving has to be possible for staying to mean anything.

Straight answers

The Boundaries, Stated Up Front

Every line here marks how far an assurance goes. If any of it is a hard requirement for your business, tell us early — the honest answer may be that we are not the right platform for you yet.

  • Written down here rather than certified elsewhere. The practices on this page are the whole of what we can evidence. We hold no SOC 2 report, no ISO 27001 certificate and no independent audit, so if your process requires a certificate from a vendor, take that as a firm answer rather than something to negotiate.
  • An honest sentence in place of a published figure. Standing behind an availability figure takes independent monitoring, and that is not something we run today — so there is no uptime guarantee here and no contractual credits. A number we cannot evidence is worth less than this sentence.
  • A small team, one time zone, fast inside our working day. We are a small team in a single time zone and we answer quickly during our working day. Cover outside those hours is not something we staff, and we would rather say so than let a night shift be assumed.
  • Independent penetration testing: not commissioned. We have not commissioned a third-party test, so there is no report we can hand you. If one is required for your review, that is worth raising before you buy.
  • Card data is handled entirely by the processors. Card data goes to the payment processors named on our integrations page, who carry their own compliance. We store no card numbers, and we make no PCI claim of our own beyond that.
  • Data residency: settle it before you buy. We do not guarantee storage in a named region today. If your business is subject to a data-residency requirement, raise it before you buy and we will tell you honestly whether we can meet it.
For your questionnaire

Six Questions Procurement Often Asks

The same boundaries as above, in the form your security reviewer is likely to paste into a spreadsheet.

  • Certifications

    Do you hold SOC 2 or ISO 27001?

    The practices on this page are the whole of what we can evidence. We hold no SOC 2 report, no ISO 27001 certificate and no independent audit, so if your process requires a certificate from a vendor, take that as a firm answer rather than something to negotiate.

  • Availability

    Is there an uptime guarantee or published availability figure?

    Standing behind an availability figure takes independent monitoring, and that is not something we run today — so there is no uptime guarantee here and no contractual credits. A number we cannot evidence is worth less than this sentence.

  • Support

    Is support available 24/7?

    We are a small team in a single time zone and we answer quickly during our working day. Cover outside those hours is not something we staff, and we would rather say so than let a night shift be assumed.

  • Testing

    Can you share a penetration-test report?

    We have not commissioned a third-party test, so there is no report we can hand you. If one is required for your review, that is worth raising before you buy.

  • Card data

    Are you PCI DSS certified?

    Card data goes to the payment processors named on our integrations page, who carry their own compliance. We store no card numbers, and we make no PCI claim of our own beyond that.

  • Data residency

    Can you guarantee data is stored in a specific region?

    We do not guarantee storage in a named region today. If your business is subject to a data-residency requirement, raise it before you buy and we will tell you honestly whether we can meet it.

Subprocessors

Who Else Touches Your Data

The named providers that process data on our behalf. Payment gateways, POS systems, delivery networks and your own SMS or email sender are contracted by you directly, so they are not our sub-processors — those are listed on integrations.

Changes are published here; where your agreement includes a sub-processor notice period, it applies. Customer-contracted connectors are on integrations. How we handle personal data is in the Privacy Policy; commercial terms are in the SaaS Agreement.

Sub-processors used by the platform
Provider Purpose Location
Google Cloud / Firebase Application hosting, database and authentication Your tenant’s agreed project region
MongoDB (hosted) Reporting database behind the analytics endpoints Region confirmed on request
Upstash Redis Cache and rate limiting Region confirmed on request
Amazon Web Services (SQS) Queue moving order events to the reporting database Region confirmed on request
Cloudinary Image storage and delivery for menu and brand assets Global CDN
Sentry Error monitoring EU or US, per account configuration
Google Maps Platform Addresses, delivery zones and driver tracking Global
OneSignal Push delivery, where our platform account is used rather than yours US

This website

Netlify (Hosting and form submissions for this website); Crisp (Chat widget on this website); Cal.com (Demo booking widget on this website — the form you fill in to pick a slot); Google Analytics (Aggregate traffic measurement — analytics consent only).

Reporting a vulnerability

If you believe you have found a security issue in Devfood, email contact@devfood.com with enough detail to reproduce it. We will acknowledge it, tell you what we intend to do, and credit you if you would like us to. Please do not test against a live customer's ordering site — ask us and we will arrange a safe way to look.

Ready to Own Your Online Ordering?

See Devfood in action with a free, no-pressure demo. We'll show you exactly how your branded apps will look and answer every question — usually within one business day.

Free demo · No commission · No minimum contract