Crubby Security
Encryption in transit and at rest, append-only audit logs, PCI-DSS via Stripe, GDPR by design. Transparency for whoever has to clear the purchase with the compliance officer.
All traffic is encrypted in transit (TLS 1.3) and at rest (AES-256). No sensitive data ever travels in the clear.
Multi-tenant by design: every query goes through requireStaff/requireAdmin, which applies the restaurantId filter. No cross-tenant data leaks.
Every administrative action is logged with actor, target, timestamp, role and payload. Append-only, unlimited retention.
Crubby never sees card numbers. Stripe handles the entire PCI-DSS Level 1 flow.
Daily backups with 7-day point-in-time recovery; weekly backups kept for 90 days. RPO < 1 hour, RTO < 4 hours.
Automatic alerting on critical errors via Sentry. Data-breach notification SLA: 72 hours, per GDPR art. 33.
Personal data hosted in the EU (Frankfurt). DPA available on request. US transfers only under SCC 2021/914.
We value responsible disclosure. If you’ve identified a security bug, write to us at security@crubby.com with the technical details (PoC, steps to reproduce, impact). Here’s what we promise:
DPA, security questionnaire, ISO/SOC2 roadmap. We answer every enterprise requirement in writing.
Email the security team