Security
Your Restaurant Data, Fully Protected
Multi-tenant isolation, JWT authentication, and role-based access control — built into the architecture from day one.
Per-Tenant Database Isolation
Every restaurant on GetRestro has its own completely separate MongoDB database. No shared tables, no shared collections. It is architecturally impossible for one restaurant's data to appear in another's account — not a policy, a structural guarantee.
JWT Authentication
Every API request requires a valid JSON Web Token tied to the specific restaurant tenant. Short-lived access tokens limit exposure. Refresh tokens are rotated on use. Tokens carry the tenant identity — no request can cross account boundaries.
Role-Based Access Control
Eight predefined roles — owner, admin, manager, cashier, waiter, kitchen, staff, rider — each with granular permission sets. A cashier cannot access inventory reports. A kitchen staff member cannot see sales figures. Configure once; enforced on every request server-side.
HTTPS Everywhere
All traffic — web app, REST API, and WebSocket — is encrypted via TLS. Unencrypted connections are rejected. Your POS, kitchen display, and manager dashboard all communicate over secure channels.
Full Audit Log
Every action — orders, voids, comps, staff logins, permission changes — is recorded with a timestamp, user identity, and tenant context. Owner and admin accounts can review the full log filtered by date, staff member, or action type.
Containerised Infrastructure
GetRestro runs on Docker with Nginx as the reverse proxy. API routes, WebSocket endpoints, and file uploads are segmented. The /api/, /socket.io/, and /uploads/ paths are blocked from public crawling.
Security Questions
Can one restaurant see another restaurant's data?
No. Every restaurant has its own isolated database. This is an architectural guarantee, not a policy.
How does GetRestro handle authentication?
JWT tokens, short-lived access + rotated refresh, with tenant identity embedded in every token. No request can cross account boundaries.
Is all data transmitted over HTTPS?
Yes. All GetRestro traffic — web app, API, WebSocket — is TLS-encrypted. Unencrypted connections are rejected.
How do I report a security concern?
Email us at hello@getrestro.com with a description of the issue. We review all security reports within one business day.
Built for restaurants you can trust with your data
Free to start. No credit card required.
Get started free