Security & compliance

Enterprise-grade security, made simple for café operators.

This page is maintained by CaféOS to answer common security and privacy questions. It describes practices as they are today and is not a certification.

Row-level security

Every query is scoped to the caller's café and role. Staff only see data that belongs to them.

Least-privilege roles

Nine granular roles (Owner, Manager, Cashier, Barista, Waiter, Inventory, Accountant, Customer, Super Admin) with fine-grained permissions.

PCI-aware payments

Card data is tokenized by your processor. CaféOS never stores PANs, CVVs or expiry dates.

Signed audit logs

Voids, refunds, discounts, cash drawer, price changes and role changes are all recorded with actor, target and reason.

Manager approvals

Sensitive actions require a manager PIN or approval. Reduce fraud and stay audit-ready.