Tenant isolation
Restaurant data is scoped by tenant in backend services, route guards, API keys and support-session boundaries.
Security posture, privacy boundaries and operational readiness for restaurants evaluating Limvero.
Controls are described as implemented product behavior, not as generic security claims.
Restaurant data is scoped by tenant in backend services, route guards, API keys and support-session boundaries.
Restaurant Cabinet and Platform Admin sessions are separated in frontend guards and backend role requirements.
Admin password policy, POS PIN policy, refresh-token rotation, logout and session invalidation reduce account risk.
Support sessions are read-only by default, time-bounded and designed for controlled troubleshooting without shared passwords.
API keys are tenant-scoped, shown once, stored hashed, protected by scopes and rate limits, and can be revoked.
Webhook destinations are validated to reduce SSRF risk and delivery events use signature and retry workflows.
Reliability expectations are tied to release gates, backups, smoke checks and incident communication.
Release checks cover route guards, source security, compose hardening, tests, typecheck, lint, build, smoke and audit.
Public and cabinet surfaces use browser hardening headers through the web runtime and production smoke checks.
Operational scripts cover PostgreSQL and Redis backups, restore checks, release manifests and rollback flow.
Webhook, report export and print workers include stale-state recovery paths for safer long-running operations.
The public status page avoids unsupported uptime claims and is ready for factual incident or maintenance updates.
Tenant export snapshots and deletion request workflows support offboarding and privacy operations.
Procurement and security-review pages describe how Limvero handles data lifecycle, recovery, incidents, subprocessors and future compliance work.
Retention categories, export snapshots, report export retention and deletion workflow boundaries.
PostgreSQL and Redis backup, restore validation, pre-migration backup and rollback boundaries.
Detection, containment, investigation, communication, recovery and post-incident review model.
Current controls, future audit roadmap and clear limits around unclaimed certifications.
Provider categories, selection status, data categories and customer notice boundaries.
Responsible reporting rules, prohibited testing actions and coordinated disclosure process.
Limvero public materials are intentionally conservative. Restaurants can see what is implemented today, what needs provider-specific work and what requires procurement review.
Review legal centerTalk through locations, POS devices, kitchen workflow, menu migration, API needs and security review before launch.