Security
Effective: June 23, 2026 Last updated: June 23, 2026
Security is a priority for Muzan. This page summarizes the measures we take to protect your data. It is informational; our binding commitments are in the Terms and the DPA (including the technical and organizational measures in Annex B).
1. Encryption
Connections to the Service use encryption in transit (HTTPS/TLS). Data is stored with reputable infrastructure providers that apply encryption at rest.
2. Access control
Access to production systems is restricted to authorized personnel on a least-privilege basis, with authentication for administrative access. Within the product, customer accounts support role-based access so you can control what your team members can do.
3. Tenant isolation
The Service is multi-tenant. We use logical access controls so that each restaurant’s data is accessible only to that account and its authorized users.
4. Infrastructure and providers
We build on established providers for hosting, database, storage, authentication, email, and payments (see our Subprocessors page). Card data is handled by Stripe, a PCI-DSS-certified processor; we do not store full card numbers.
5. Secure development
We follow secure-development practices, keep dependencies maintained, and review changes before release. We aim to address known security issues promptly.
6. Backups and resilience
We rely on managed infrastructure with backup and recovery capabilities to reduce the risk of data loss and support availability.
7. Logging and monitoring
We log and monitor relevant system activity to help detect, investigate, and respond to operational and security events.
8. Incident response and breach notification
We maintain an incident-response process. If we become aware of a personal data breach affecting data we process on a customer’s behalf, we will notify the customer without undue delay and assist as set out in the DPA.
9. Data location and transfers
We are based in the United States and use providers that may process data in the U.S. and other countries, with appropriate transfer safeguards where required. See our Privacy Policy and DPA for details.
10. Certifications
We rely on the certifications and attestations of our infrastructure providers (for example, Stripe’s PCI-DSS compliance). We do not currently hold our own formal certification such as SOC 2.
11. Your responsibilities
Security is shared. Please use a strong, unique password, keep your credentials confidential, manage your team’s roles carefully, and notify us promptly of any suspected unauthorized access.
12. Reporting a vulnerability
If you discover a potential security issue, report it responsibly to support@muzan.app. Please give us a reasonable opportunity to address it before public disclosure, and do not access, modify, or delete data that is not yours or degrade the Service while testing. We appreciate coordinated disclosure.