Skip to content
Security

What We Do, and What We Will Not Claim

A short, checkable account of how Devfood handles your data — and an equally clear list of the assurances we are not in a position to give.

Read the second half of this page first. Most security pages are a list of reassurances. The part of this one worth your time is what we do not claim — if one of those items is a requirement for you, you will find out here rather than three weeks into a procurement review.

Tenant isolation

Every business on the platform is a separate tenant. Menus, orders, customers and staff accounts are scoped to that tenant, and a request carrying one tenant’s credentials cannot read another’s records.

Access control by role

Staff accounts are role-scoped — a counter user, an outlet manager and an owner see different things. Outlet staff are limited to their own outlet’s data rather than the whole group’s.

Card details never touch us

Payments are handled by the processor’s own hosted flows. Card numbers are entered into the processor, not into our apps, and we never store them.

Encryption in transit

Every connection between the apps and the platform is served over HTTPS. This website enforces HSTS and ships a restrictive content-security policy.

Your accounts, your money

Payment accounts belong to you. Settlement runs from the processor to your bank without passing through an account of ours, so a dispute with us is never a dispute about your takings.

Your data is exportable

Customer records, order history and reporting can be exported from the admin dashboard. Data portability is a product feature rather than a favour, because leaving has to be possible for staying to mean anything.

Stated Plainly

What We Do Not Claim

Every line here is something we could have implied and have not. If any of it is a hard requirement for your business, tell us early — the honest answer may be that we are not the right platform for you yet.

  • No security certification. We hold no SOC 2 report, no ISO 27001 certificate and no independent audit. Anyone who needs one from a vendor should treat that as disqualifying rather than negotiable.
  • No uptime figure and no service level. We publish no uptime guarantee and no contractual credits, because we do not run the independent monitoring that would let us stand behind either. A number we cannot evidence is worth less than this sentence.
  • No round-the-clock support. We do not offer 24/7 cover. We are a small team in a single time zone — we answer quickly during our working day and we do not pretend there is a night shift.
  • No penetration-test report to share. We have not commissioned a third-party test, so we cannot hand you one.
  • No PCI compliance claim on our side. Card data is handled by the payment processors named below, who carry their own compliance. We do not store card numbers, and we make no assertion beyond that.
  • No guarantee of a specific data region. If your business is subject to a data-residency requirement, raise it before you buy and we will tell you honestly whether we can meet it.
Subprocessors

Who Else Touches Your Data

The third parties the platform sends data to on your behalf. This list is meant to be complete — a partial one would be worse than none, because publishing it asserts that it is finished.

Service Purpose Data handled
Stripe Card and wallet payments Payment details, order amount, customer email
Finix Card payments and card-present terminals Payment details, order amount
Paytrail Nordic bank and card payments Payment details, order amount
Twilio One-time passcodes and SMS order updates Phone number, message content
SendGrid Transactional email Email address, message content
OneSignal Push notifications Device push token, notification content
Google Maps Platform Address lookup, delivery zones, live tracking Delivery address, driver location
Cloudinary Menu image hosting and delivery Menu images uploaded by the outlet

Each of these is contracted by you, in your name — see Integrations. How we handle personal data is set out in the Privacy Policy, and the commercial terms are in the SaaS Agreement.

Reporting a vulnerability

If you believe you have found a security issue in Devfood, email contact@devfood.com with enough detail to reproduce it. We will acknowledge it, tell you what we intend to do, and credit you if you would like us to. Please do not test against a live customer's ordering site — ask us and we will arrange a safe way to look.

Ready to Own Your Online Ordering?

See Devfood in action with a free, no-pressure demo. We'll show you exactly how your branded apps will look and answer every question — usually within 24 hours.

Free demo · No commission · No minimum contract