Security and control

Restaurant data should stay with the right restaurant.

MenuBeacon layers authentication, permissions, tenant scoping, validation, rate limits, and operational checks around every workflow. This page explains what is implemented, where third parties are involved, and what we do not claim.

Account and session controls

Owner sessions use secure, httpOnly cookies in production, state-changing requests are protected against cross-site request forgery, and passwords are stored as bcrypt hashes rather than plain text.

Roles and restaurant scope

Owner, manager, kitchen, waiter, and related workflows have explicit permissions. Server routes re-check both the actor and the restaurant instead of relying on what the browser hides.

Protected privileged work

Sensitive super-admin operations use step-up controls, while staff access can be limited with role permissions, PIN sessions, account status, and token revocation.

Validated uploads

Uploaded files are checked for allowed type, size, and image safety before storage. Public file delivery is separated from application configuration and server code.

Payment separation

Where card payment is available, Stripe handles the payment interface and connected-account flow. MenuBeacon records the order and payment status; it does not ask restaurants to paste card numbers into the dashboard.

Operational safeguards

Production configuration checks, rate limits, redacted logs, health endpoints, backups, deployment verification, and rollback procedures protect the service boundary.

The core boundary

Identity first. Restaurant scope second. Permission every time.

A signed-in screen is not the security boundary. The server identifies the actor, resolves the restaurant they are allowed to reach, checks the required permission, and scopes the data query before a record is read or changed.

  1. 1

    Authenticate

    Verify the owner session or a scoped staff session.

  2. 2

    Resolve restaurant

    Bind the request to a restaurant the actor can reach.

  3. 3

    Check permission

    Require the role and capability for this exact operation.

  4. 4

    Validate input

    Apply closed schemas, limits, and business rules.

  5. 5

    Read or write scoped data

    Use restaurant-bound queries and record sensitive activity.

Zuzu considering whether a request is allowed

Zuzu’s extra boundary

The AI does not become the permission system.

Zuzu can suggest a MenuBeacon action, but the application remains the authority. A persuasive prompt cannot grant a role, switch restaurants, reveal a credential, or create a tool that does not exist.

  • The model receives a minimal restaurant context rather than a database or secret store.
  • Every tool re-checks authentication, restaurant scope, role, plan, and market capability.
  • No tool accepts a restaurant ID from the conversation or offers general HTTP, SQL, shell, or code execution.
  • High-impact actions are stored for a separate, actor-bound confirmation and expire if not approved.
  • Input and output screening blocks common jailbreak and credential-shaped content before it is stored or returned.
  • Global, restaurant, usage, rollout, and emergency-stop controls can disable Zuzu without disabling MenuBeacon.

See Zuzu’s capabilities and limits →

Data handling

Clear roles for restaurant, diner, MenuBeacon, and provider.

Restaurants control their customer order and contact data. MenuBeacon processes that data to provide the service, while specific providers handle the narrow jobs disclosed in the Privacy Policy.

Restaurant

Controls its menu, staff access, customer-data purposes, retention choices, taxes, and fulfillment.

MenuBeacon

Runs the menu, ordering, account, analytics, and operational workflows under the published terms.

Stripe

Handles supported card and wallet payment flows when the restaurant enables online payment.

Infrastructure providers

Host, store, deliver, locate, message, or protect data only for their disclosed service role.

Read the Privacy Policy and provider list →

What we do not claim

No borrowed badges or implied certification.

MenuBeacon does not claim SOC 2, ISO 27001, PCI assessor certification, a public bug bounty, or an independent penetration-test seal unless and until that evidence exists. Stripe’s role does not turn MenuBeacon into a certified payment processor.

Report a security issue

Send enough detail for us to reproduce it.

Email support@menubeacon.com. Do not access another person’s data, disrupt service, or publish sensitive details while a report is being investigated.

View security.txt →

Test the workflow before you put it on a table.

Use the shared demo for product behaviour, or create a free restaurant to test your own menu and roles.

Create your free menu

Want to look around first? Open the live demo — a fully set-up restaurant, no sign-up.

Free forever · Pro $20/mo · No commission, cancel anytime