Security
Your books are yours alone.
The separation is in the design, not in a policy document.
A schema per restaurant
Each workspace is its own database schema. A query cannot reach another restaurant's rows because there is no shared table to reach.
Two-factor sign-in
Time-based codes on every account. Invite-only workspaces; nobody signs themselves up.
Six roles
Owner, partner, accountant, manager, kitchen, cashier. Each screen and each action is gated by role and by branch.
Scoped API keys
A key posts receipts and nothing else. Shown once, stored as a hash, revocable.
Exports, always
Every screen exports CSV. The full journal exports in accountant formats. Your data leaves whenever you ask.
Hosting
Application and database hosted in the EU, edge and DNS on Cloudflare.
Questions about data handling go to hello@ottofnb.com. Vulnerability reports: security.txt.