Security
Last updated September 27, 2026
The short version
- Everything is encrypted in transit and at rest, and connection tokens are encrypted a second time by us.
- Every change is checked automatically for any query that could show one shop another shop's data.
- Daily encrypted backups, each one checked after it's made.
- We're small and say so: no SOC 2 report yet, one person with access.
This box is a summary, not the agreement. Everything below it is.
What protects your data
Encryption
- All traffic is HTTPS only.
- The database is encrypted at rest by Supabase.
- Google and Square access tokens are encrypted again by Cortado (AES-256-GCM) before they are stored, so a copy of the database alone cannot use them.
- Backups are encrypted before they leave the machine that makes them. Backblaze and iCloud hold files they cannot read.
Accounts and access
- Passwords and shop PINs are stored only as salted hashes.
- Sessions are signed, expire after a period of inactivity the owner chooses, and last seven days at most.
- Sign-in, password reset and PIN entry are rate limited.
- Deleting an account needs the password, the shop name typed out and a code sent by email.
- The database key that can read every shop is kept only in the hosting environment and on the operator's own machine. It is never given to the build and test system.
Keeping shops apart
- Every query for shop data is filtered by the shop it belongs to.
- An automated check runs on every change, looks for any query that is not filtered, and fails the build if it finds one.
Resilience
- Encrypted backups are taken daily, and each one is decrypted and read back after it is written, to prove it can be restored.
- A failed backup or an unusual burst of errors alerts the operator by email.
- The staff counting screen keeps working without a signal and sends when it can.
People
- One person operates Cortado and is the only one with access to production systems.
- Customer data is looked at only to fix a problem the customer reported or to keep the service running.
What we don't have yet
Said plainly, because you would ask:
- No SOC 2 or ISO 27001 certification. Our hosting and database providers have them; we don't yet.
- No external penetration test yet.
- No single sign-on or two-factor sign-in for owner accounts yet. Use a long, unique password.
- No uptime guarantee during early access.
If your business needs any of these before it can use Cortado, email us. It helps us decide what comes next.
What you can do
- Use a password you use nowhere else.
- Change the staff PIN when someone leaves, and sign out all staff phones from the location's settings.
- Pick a shorter sign-out time in Preferences if the owner app is open on a shared device.
- Keep customers' details and sensitive staff information out of notes.
Reporting a problem
Email sen@cortado.services with what you found and how to reproduce it. We reply within two working days, keep you updated, and credit you when it's fixed if you would like. Good-faith research under the acceptable use policy is welcome. Our contact details are also in security.txt.
If something goes wrong
If a breach affects your data, we email you within 72 hours of finding out, with what happened, what was affected, and what we are doing about it.
Questions about any of this? Email sen@cortado.services and a person will answer.