Restore

Security

Last reviewed September 5, 2026

Restore protects restaurant compliance, advisory, marketplace, and billing workflows using layered application and provider controls. This page describes implemented controls without claiming a certification Restore has not earned.

Identity and Access

Application and Data Controls

Service Providers and Resilience

Vercel serves the web application, Render operates the API, Supabase hosts PostgreSQL, Stripe processes payments, and Resend delivers transactional email. Restore maintains deployment history, an incident-response plan, and repository-controlled automation for encrypted independent backups. Provider-level backup retention and restore drills are verified operationally rather than assumed from application code. Payment-card numbers are handled by Stripe rather than Restore.

Responsible Disclosure

Email security@restorecc.io with the affected URL, impact, reproduction steps, and relevant request IDs. Do not access other users' data, disrupt service, perform denial-of-service testing, or publish sensitive findings before Restore has had a reasonable opportunity to investigate. We will acknowledge good-faith reports and coordinate remediation.