Skip to content

Security

Conservative security practices for restaurant operations.

BranchOrbit uses tenant-scoped access patterns, encrypted integration tokens, role-aware admin surfaces, and secure deployment practices. No public page can guarantee absolute security, but the platform is designed with practical controls.

Tenant isolation

Application access is scoped by tenant, branch, role, and permission-aware API paths.

Encrypted POS tokens

POS access and refresh tokens are encrypted server-side and are never sent to the frontend.

Payment boundaries

BranchOrbit does not claim to store full card numbers; card processing is handled by payment processors such as Stripe.