Security & compliance
Enterprise-grade security, made simple for café operators.
This page is maintained by CaféOS to answer common security and privacy questions. It describes practices as they are today and is not a certification.

Row-level security
Every query is scoped to the caller's café and role. Staff only see data that belongs to them.
Least-privilege roles
Nine granular roles (Owner, Manager, Cashier, Barista, Waiter, Inventory, Accountant, Customer, Super Admin) with fine-grained permissions.
PCI-aware payments
Card data is tokenized by your processor. CaféOS never stores PANs, CVVs or expiry dates.
Signed audit logs
Voids, refunds, discounts, cash drawer, price changes and role changes are all recorded with actor, target and reason.
Manager approvals
Sensitive actions require a manager PIN or approval. Reduce fraud and stay audit-ready.