What We Do, and Where the Boundaries Are
A short, checkable account of how Devfood handles your data — and an equally clear account of how far our assurances go.
Tenant isolation
Every business on the platform is a separate tenant. Menus, orders, customers and staff accounts are scoped to that tenant, and a request carrying one tenant’s credentials cannot read another’s records.
Access control by role
Staff accounts are role-scoped — a counter user, an outlet manager and an owner see different things. Outlet staff are limited to their own outlet’s data rather than the whole group’s.
Card details never touch us
Payments are handled by the processor’s own hosted flows. Card numbers are entered into the processor, not into our apps, and we never store them.
Encryption in transit
Every connection between the apps and the platform is served over HTTPS. This website enforces HSTS and ships a restrictive content-security policy.
Your accounts, your money
Payment accounts belong to you. Settlement runs from the processor to your bank without passing through an account of ours, so a dispute with us is never a dispute about your takings.
Your data is exportable
Customer records, order history and reporting can be exported from the admin dashboard. Data portability is a product feature rather than a favour, because leaving has to be possible for staying to mean anything.
The Boundaries, Stated Up Front
Every line here marks how far an assurance goes. If any of it is a hard requirement for your business, tell us early — the honest answer may be that we are not the right platform for you yet.
- Written down here rather than certified elsewhere. The practices on this page are the whole of what we can evidence. We hold no SOC 2 report, no ISO 27001 certificate and no independent audit, so if your process requires a certificate from a vendor, take that as a firm answer rather than something to negotiate.
- An honest sentence in place of a published figure. Standing behind an availability figure takes independent monitoring, and that is not something we run today — so there is no uptime guarantee here and no contractual credits. A number we cannot evidence is worth less than this sentence.
- A small team, one time zone, fast inside our working day. We are a small team in a single time zone and we answer quickly during our working day. Cover outside those hours is not something we staff, and we would rather say so than let a night shift be assumed.
- Independent penetration testing: not commissioned. We have not commissioned a third-party test, so there is no report we can hand you. If one is required for your review, that is worth raising before you buy.
- Card data is handled entirely by the processors. Card data goes to the payment processors named on our integrations page, who carry their own compliance. We store no card numbers, and we make no PCI claim of our own beyond that.
- Data residency: settle it before you buy. We do not guarantee storage in a named region today. If your business is subject to a data-residency requirement, raise it before you buy and we will tell you honestly whether we can meet it.
Six Questions Procurement Often Asks
The same boundaries as above, in the form your security reviewer is likely to paste into a spreadsheet.
-
Certifications
Do you hold SOC 2 or ISO 27001?
The practices on this page are the whole of what we can evidence. We hold no SOC 2 report, no ISO 27001 certificate and no independent audit, so if your process requires a certificate from a vendor, take that as a firm answer rather than something to negotiate.
-
Availability
Is there an uptime guarantee or published availability figure?
Standing behind an availability figure takes independent monitoring, and that is not something we run today — so there is no uptime guarantee here and no contractual credits. A number we cannot evidence is worth less than this sentence.
-
Support
Is support available 24/7?
We are a small team in a single time zone and we answer quickly during our working day. Cover outside those hours is not something we staff, and we would rather say so than let a night shift be assumed.
-
Testing
Can you share a penetration-test report?
We have not commissioned a third-party test, so there is no report we can hand you. If one is required for your review, that is worth raising before you buy.
-
Card data
Are you PCI DSS certified?
Card data goes to the payment processors named on our integrations page, who carry their own compliance. We store no card numbers, and we make no PCI claim of our own beyond that.
-
Data residency
Can you guarantee data is stored in a specific region?
We do not guarantee storage in a named region today. If your business is subject to a data-residency requirement, raise it before you buy and we will tell you honestly whether we can meet it.
Who Else Touches Your Data
The named providers that process data on our behalf. Payment gateways, POS systems, delivery networks and your own SMS or email sender are contracted by you directly, so they are not our sub-processors — those are listed on integrations.
Changes are published here; where your agreement includes a sub-processor notice period, it applies. Customer-contracted connectors are on integrations. How we handle personal data is in the Privacy Policy; commercial terms are in the SaaS Agreement.
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud / Firebase | Application hosting, database and authentication | Your tenant’s agreed project region |
| MongoDB (hosted) | Reporting database behind the analytics endpoints | Region confirmed on request |
| Upstash Redis | Cache and rate limiting | Region confirmed on request |
| Amazon Web Services (SQS) | Queue moving order events to the reporting database | Region confirmed on request |
| Cloudinary | Image storage and delivery for menu and brand assets | Global CDN |
| Sentry | Error monitoring | EU or US, per account configuration |
| Google Maps Platform | Addresses, delivery zones and driver tracking | Global |
| OneSignal | Push delivery, where our platform account is used rather than yours | US |
This website
Netlify (Hosting and form submissions for this website); Crisp (Chat widget on this website); Cal.com (Demo booking widget on this website — the form you fill in to pick a slot); Google Analytics (Aggregate traffic measurement — analytics consent only).
Reporting a vulnerability
If you believe you have found a security issue in Devfood, email contact@devfood.com with enough detail to reproduce it. We will acknowledge it, tell you what we intend to do, and credit you if you would like us to. Please do not test against a live customer's ordering site — ask us and we will arrange a safe way to look.
Ready to Own Your Online Ordering?
See Devfood in action with a free, no-pressure demo. We'll show you exactly how your branded apps will look and answer every question — usually within one business day.
Free demo · No commission · No minimum contract