Home Platform Contact Security
๐Ÿ›ก๏ธ Security

Your restaurant data is
our top priority

Enterprise-grade security built into every layer of OpenDine. From encryption to access controls โ€” here's how we protect you.

๐Ÿ”
AES-256 Encryption
๐Ÿ”’
TLS 1.2+ in Transit
๐Ÿ‘ฅ
Role-Based Access
๐Ÿ“‹
Audit Logging
๐ŸŒ
GDPR & DPDPA Ready
๐Ÿข
Row-Level Security

Our Security Principles

Security isn't a feature โ€” it's the foundation. We build with these principles at every layer.

๐Ÿ”

Encryption Everywhere

All data is encrypted at rest with AES-256 and in transit with TLS 1.2+ using strong cipher suites. Encryption keys are managed separately from data.

  • AES-256 at rest on all database storage
  • TLS 1.2+ enforced on all connections
  • Certificate pinning on mobile/web clients
  • HSTS enabled with strong security headers
๐Ÿ‘ฅ

Zero-Trust Access

Every request is authenticated and authorized. We use the principle of least privilege โ€” each user and service gets only the permissions they need.

  • RBAC (Role-Based Access Control) on all users
  • Row-level security by tenant_id in database
  • Multi-factor authentication support
  • API key scoping with minimal permissions
๐Ÿ“‹

Complete Audit Trail

Every significant action on the platform is logged with actor, timestamp, and IP. Logs are immutable and retained for 2 years for forensic analysis.

  • All admin-level actions logged
  • Data export events tracked
  • Login/logout timestamps per session
  • Immutable audit log architecture
๐Ÿข

Multi-Tenant Isolation

Your restaurant's data is completely isolated from all other tenants. Database queries are scoped by tenant_id โ€” there's no cross-tenant data leakage.

  • PostgreSQL RLS (Row-Level Security) enforced
  • Separate data partitions per tenant
  • No shared caching of tenant data
  • Isolated API keys per outlet
๐Ÿ”„

Business Continuity

99.9% uptime SLA backed by automated failover, regular backups (3x daily), and disaster recovery procedures with tested RTO/RPO targets.

  • Automated daily offsite backups
  • Real-time replication across availability zones
  • Automated failover within 60 seconds
  • Enterprise SLA with financial penalties
๐Ÿงช

Continuous Security Testing

We run automated vulnerability scanning on every code push, conduct quarterly penetration tests with third-party security firms, and maintain a bug bounty program.

  • SAST + DAST in CI/CD pipeline
  • Third-party penetration testing (annual)
  • Dependency vulnerability scanning
  • Bug bounty for responsible disclosure

Infrastructure Architecture

Built on Google Cloud Platform with security at every layer

๐ŸŒ

Your Restaurant

Browser / App / KDS Device

โ†’
๐Ÿ”’

Cloudflare WAF

DDoS + Firewall + CDN

โ†’
โšก

GCP Mumbai

K8s Cluster ยท Load Balancer

โ†’
๐Ÿ—„๏ธ

PostgreSQL DB

Managed DB ยท AES-256 ยท RLS

99.9%
Uptime SLA
<60s
Failover Time
3ร— daily
Automated Backups
GDPR
Compliant Region

Compliance & Certifications

We meet global standards for data protection, security, and operational excellence.

๐ŸŒ

GDPR (EU)

OpenDine is fully compliant with the General Data Protection Regulation. We provide data portability, the right to erasure, and consent management for all EU users. Our DPA (Data Processing Agreement) is available on request.

โœ“ Right to access & portability
โœ“ Right to erasure (30-day SLA)
โœ“ Data Processing Agreement
๐Ÿ‡ฎ๐Ÿ‡ณ

India DPDPA

In compliance with India's Digital Personal Data Protection Act. We are registered as a Data Fiduciary and maintain all required records of processing activities. Consent capture, purpose limitation, and data minimization are built into our architecture.

โœ“ Data Fiduciary registration
โœ“ Consent management built-in
โœ“ GRI-compliant data handling
๐Ÿฆ

SOC 2 Type II

OpenDine maintains SOC 2 Type II compliance (annual audit). This covers the Trust Services Criteria: Security, Availability, Confidentiality, and Processing Integrity. Our most recent audit report is available to Enterprise customers under NDA.

โœ“ Annual third-party audit
โœ“ Security & Availability controls
โœ“ Enterprise audit report (NDA)
๐Ÿ’ณ

PCI DSS (Planned)

OpenDine does not store card data. Payment processing is handled by certified PCI DSS-compliant third-party providers (Razorpay, Stripe). Our roadmap includes direct PCI DSS Level 1 compliance by Q4 2026.

โœ“ No card data stored on platform
โœ“ Stripe/Razorpay integrations
โœ“ PCI DSS Level 1 roadmap Q4 2026

Incident Response

We have a structured, tested incident response process to protect you in the rare event of a security issue.

1

Detection & Alerting

Automated monitoring systems scan for anomalies 24/7. Security alerts escalate to our on-call security team within 5 minutes of detection.

2

Triage & Assessment

The security team classifies severity (Critical / High / Medium / Low), determines scope, and activates the appropriate response team within 30 minutes.

3

Containment

Affected systems are isolated immediately. Automated playbooks can contain common threats within 60 seconds without human intervention.

4

Customer Notification

Affected customers are notified within 72 hours per GDPR Article 33. Enterprise customers receive direct notification within 4 hours of confirmed breach.

5

Post-Incident Review

After every significant incident, we conduct a blameless post-mortem within 7 days, document lessons learned, and implement preventive changes within 30 days.

Responsible Disclosure

Found a security vulnerability?

We take security seriously and welcome responsible disclosure from security researchers and customers. If you discover a vulnerability in OpenDine, please report it to us immediately and we will work with you to resolve it quickly.

Scope: All OpenDine production infrastructure, web application, and APIs. Excluded: social engineering, DoS attacks on our infrastructure, and issues already known to us.

We commit to: acknowledge receipt within 24 hours, provide a initial assessment within 5 business days, and work toward a fix within 90 days for confirmed vulnerabilities.

๐Ÿ“ง Report to: security@opendine.com (PGP preferred for sensitive reports)

Enterprise Security Report

Available to Enterprise customers under NDA. Includes full penetration test results, security architecture details, and our latest SOC 2 audit report.

๐Ÿ“‹ Request Security Report