Trust

Security at Floor Boss.

Floor Boss sits on top of the systems that run your restaurant, so we treat security as a first-order requirement — not an afterthought.

Last updated: February 2026

Data protection

  • Encryption in transit — all traffic is protected with TLS.
  • Encryption at rest — stored data is encrypted using industry-standard algorithms.
  • Least privilege — access to customer data is limited to those who need it for their role, and is logged and reviewed.
  • Data ownership — your operational data is yours; it is never sold, and you can export or delete it at any time.

Infrastructure

  • Hosted on major cloud infrastructure whose data centers hold recognized third-party certifications (such as SOC 2 and ISO 27001). Our current hosting providers can be confirmed on request.
  • Network isolation, managed firewalls, and a regular patching cadence.
  • Automated backups, with restore procedures maintained and exercised.

Access & authentication

  • Floor Boss connects to your tools using scoped, revocable credentials — you can disconnect at any time.
  • Administrative access requires strong authentication, including multi-factor authentication.
  • We never ask you to share passwords; you authorize connections through each provider.

Monitoring & response

  • Logging and monitoring across the service, to help us detect unusual activity.
  • An incident-response process with defined roles and escalation paths. If an incident affects your data, we will notify you without undue delay and within the timeframes required by applicable law.
  • Ongoing review of dependencies, with remediation prioritized by risk.

Application security

  • Peer review of code changes, and separation between development and production environments.
  • Monitoring dependencies for known vulnerabilities, with remediation prioritized by risk.
  • Managing credentials and secrets through purpose-built tooling rather than source code.
  • Testing changes before release, and welcoming third-party security review.

People and vendors

  • Personnel with access to customer data are bound by confidentiality obligations.
  • We promote security awareness across the team as part of how we work.
  • Access to production systems is granted on a need-to-know basis and reviewed as roles change.
  • We assess the security and privacy practices of vendors and subprocessors before engaging them.

Availability and business continuity

  • Automated, encrypted backups, with recovery procedures maintained for the data we hold.
  • Infrastructure designed for resilience, so that a single component failure should not take the service down.
  • Recovery planning appropriate to the scale and criticality of the service.
  • By design, Floor Boss is an assistive layer — your POS and scheduling systems remain your systems of record, so an interruption to Floor Boss does not stop your restaurant from operating.

Compliance

Our controls are designed to align with widely used industry frameworks, including the SOC 2 Trust Services Criteria, and with applicable data-protection laws such as the GDPR and CCPA. We support customers' own compliance obligations by offering a Data Processing Agreement and a current subprocessor list on request.

If you need documentation for a vendor security review, contact security@floorboss.ai and we will share what we have. For data-handling specifics, see Your data policy.

Responsible disclosure

If you believe you have found a security issue, please email security@floorboss.ai. We appreciate good-faith reports and will work with you to resolve them.