Security
Last reviewed September 5, 2026
Restore protects restaurant compliance, advisory, marketplace, and billing workflows using layered application and provider controls. This page describes implemented controls without claiming a certification Restore has not earned.
Identity and Access
- Administrator TOTP multi-factor authentication.
- Short, versioned, revocable signed sessions in Secure, HttpOnly, SameSite cookies.
- Salted scrypt password hashing and hashed, expiring reset tokens.
- Persistent account-and-IP authentication throttling and uniform login failure messages.
- Role checks for restaurant, provider, staff, and full-administrator actions.
Application and Data Controls
- HTTPS with HSTS; authenticated TLS connections to hosted PostgreSQL.
- Parameterized SQL, input allowlists, bounded request bodies, CSRF origin validation, and Stripe webhook signature verification.
- Forced Row Level Security and revoked anonymous database-table access.
- Private evidence downloads, strict file size/type/signature checks, and attachment delivery.
- Security headers for framing, MIME sniffing, referrers, browser capabilities, and content loading.
Service Providers and Resilience
Vercel serves the web application, Render operates the API, Supabase hosts PostgreSQL, Stripe processes payments, and Resend delivers transactional email. Restore maintains deployment history, an incident-response plan, and repository-controlled automation for encrypted independent backups. Provider-level backup retention and restore drills are verified operationally rather than assumed from application code. Payment-card numbers are handled by Stripe rather than Restore.
Responsible Disclosure
Email security@restorecc.io with the affected URL, impact, reproduction steps, and relevant request IDs. Do not access other users' data, disrupt service, perform denial-of-service testing, or publish sensitive findings before Restore has had a reasonable opportunity to investigate. We will acknowledge good-faith reports and coordinate remediation.