Security & Compliance
Last updated · June 2026
Data isolation
Each workspace runs on database-per-tenant isolation. Recipes, invoices, costing history, and uploaded media are stored in a dedicated tenant database — never commingled with other operators. Cross-tenant access is blocked at the application and database layers.
Encryption
All traffic uses TLS in transit. Sensitive credentials, two-factor secrets, and integration tokens are encrypted at rest using application-level encryption. Session cookies are signed and scoped to your workspace domain.
Audit logs
Security-sensitive actions — logins, permission changes, API key issuance, and integration updates — are recorded in a tenant-scoped audit log visible to workspace owners. Entries include actor, action, and timestamp for accountability and SOC2-style review.
SSO & two-factor authentication
Workspaces support Google SSO and optional SAML SSO for enterprise identity providers. Team members can enable TOTP-based two-factor authentication on their accounts. Owners control who is invited and which roles can access costing, inventory, and billing settings.
Backup & recovery
Central and tenant databases are backed up on a scheduled cadence with point-in-time recovery targets appropriate for production hospitality workloads. Backups are encrypted and stored separately from primary database infrastructure.
Subprocessors
We use vetted infrastructure and service providers to operate the platform, including cloud hosting, email delivery, payment processing (Stripe), and optional AI document/vision providers when you invoke scanning features. A current subprocessor list is available on request; we notify operators of material changes.
Questions? See FAQ or email info@culinaryanalytics.com.
Ready to cost your first dish?
Create a free workspace — no credit card required.