Security Practices

This page describes how we approach security for FoodOrders.ai. It reflects our own operating practices and is not an independent audit or certification of this application.

Platform infrastructure

Our application is built using Lovable, a platform that maintains SOC 2 Type II compliance and ISO 27001:2022 certification. Those certifications apply to Lovable and its defined systems and controls, not to our company or this application. We use that infrastructure as one part of a broader security program.

Access & tenant isolation

Merchant data is scoped per tenant and protected with row-level access rules enforced in the database. Staff access to a merchant workspace is granted through invitations and role assignments controlled by the account owner.

Data in transit & at rest

Traffic to the application is served over HTTPS. Data is stored with our managed database and storage providers, which encrypt data at rest. Payment card details are handled by Stripe and never stored on our systems.

Connected services

We rely on established providers for telephony, voice, email and payments. Credentials for these services are stored as server-side secrets and are never exposed to the browser. Inbound webhooks are signature-verified before processing.

Responsible AI

Our AI ordering agents operate within defined menus, prices and business rules, with server-side validation of every order. We follow governance practices informed by ISO/IEC 42001 principles covering transparency, human oversight and accountability.

Reporting a vulnerability

If you believe you have found a security issue, please contact us at security@foodorders.ai. We appreciate responsible disclosure and will respond as quickly as we can.

Security, Privacy & Responsible AI

Our application is built using Lovable, a platform that maintains SOC 2 Type II compliance and ISO 27001:2022 certification. We combine this security-focused infrastructure with privacy-conscious data practices, GDPR-supporting safeguards, and responsible AI governance informed by ISO/IEC 42001 principles.

Platform certifications apply to Lovable and its defined systems and controls. They do not constitute independent SOC 2 or ISO certification of our company or this application. Compliance responsibilities are shared across our platform providers, application controls, connected services and internal operating practices.

  • SOC 2 Type II

    Built using a platform subject to independent security-control assessment.

  • ISO 27001:2022

    Supported by an information-security management framework certified at the platform level.

  • GDPR

    Designed with privacy, transparency, data minimization and user rights in mind.

  • Responsible AI

    AI practices informed by ISO/IEC 42001 principles for accountable AI management.