Cibuscibus.
Security & compliance

A platform built for the trust restaurants need.

Cibus combines role and capability checks, restaurant-scoped access, database tenant boundaries, payment records and privacy-conscious observability. We review the controls and evidence that apply to each proposed workflow.

Capability matrix
Roles × sensitive actions
Illustrative
RoleRefundVoidDiscountMenu editRole change
CSCashier
SVServer
MGManager
OWOwner
Control evidence · illustrative
  • RecordedPayment record
    Order and allocation context
  • CheckedRole capability
    Action permission
  • ScopedRestaurant access
    Assigned restaurant
Roleaccess defaults

Role templates establish a practical starting point.

Scoperestaurant access

Access follows assigned restaurant and portfolio scope.

RLSdata boundary

Restaurant data is scoped with database policies.

Reviewworkflow evidence

Current control coverage is documented for the proposed scope.

The pain

Where 'good enough' security fails restaurants

Everyone has the same login
Cashiers can refund, servers can edit menus — and no one can trace who did what.
Partner access is too broad
External sales agents see customer data they should never touch.
Customer data scattered
PII spread across POS, marketing tool and email provider — consent unclear.
No tenant boundaries
Multi-tenant SaaS where one customer's data can leak into another's reports.
No audit trail on sensitive actions
Refunds, voids and role changes happen without an investigable record.
Old way vs. Cibus

From open by default to scoped by design

Open by default
  • Shared logins across staff
  • Partner access broader than needed
  • Customer PII in unmanaged tools
  • No clear tenant boundaries
  • Sensitive actions untraceable
With Cibus
  • Capability-aware permissions per role
  • Scoped restaurant access for partners and managers
  • Documented customer-data responsibilities
  • Restaurant scope enforced with database policies
  • Current activity-record coverage reviewed by workflow
Workflow

How control is established and maintained

  1. 01Define
    Define roles and capabilities
    Start from sensible defaults or shape roles to your operation.
  2. 02Scope
    Scope access per restaurant
    Staff and partners receive access according to their assigned restaurant scope.
  3. 03Operate
    Operate with capability checks
    Sensitive actions require the right capability; nothing implicit.
  4. 04Review
    Review supported records
    Confirm the payment and operational activity context available for each selected workflow.
  5. 05Document
    Set data-handling responsibilities
    Define processing roles, retention requirements and rights-request routes before go-live.
Controls

What's in the trust layer

Role-based access (RBAC)
Cashier, server, manager, owner, partner and admin roles with sensible defaults.
Capability-aware permissions
Sensitive actions (refunds, voids, role changes, menu edits) gated per capability — not just per role.
Scoped restaurant access
Users and partners receive access according to their assigned restaurant scope.
Tenant boundaries
Restaurant-scoped data is protected with database row-level security policies.
Payment and activity records
Payment workflows retain order and allocation context. Coverage for other sensitive actions is reviewed for the workflows in scope.
Privacy and GDPR governance
The applicable agreement and privacy information define processing roles, authorised access, retention and rights-request routes for the deployment.
Privacy-conscious observability
Error telemetry applies PII-scrubbing controls before events are sent to monitoring.
Payments isolated from card data
Payment-card entry and processing are handled through Stripe; Cibus application records do not store raw card numbers.
Control review
Buyers can review the controls, dependencies and available evidence for their proposed Cibus scope during discovery.
Governance

Decision-making stays with the owner

Owner-reviewed AI
AI Insights and Stories surface recommendations and drafts — the owner decides.
Consent-aware deployment
Consent mechanisms for selected customer and marketing workflows are reviewed against channel and market requirements.
Defined data responsibilities
Controller and processor allocation, access, retention and request routing are documented for the selected deployment.
The trust layer

Not open by default. Scoped access and tenant boundaries by design.

Role and capability checks, restaurant scope, row-level security, privacy-conscious observability and defined payment records provide a reviewable control foundation. Current evidence is assessed for the workflows in scope.

FAQ

Security and compliance questions

Is access role-based or capability-aware?

Both. Roles give sensible defaults; capabilities gate sensitive actions per user.

Discuss controls, roles and tenant isolation.

See how Cibus connects service, kitchen operations, payments, reporting, customer engagement and delivery into one restaurant operating system.