QwikPass
Evidence-limited control statementSecurity & access

Clear access for every organization, outlet and role.

This page describes controls implemented in the local pilot build and lists the production gates still open. It is not a certification, compliance statement or production-security claim.

Implemented locally

Controls already enforced by the application.

Tenant context

Protected requests resolve the current organization membership and authorized outlet assignment.

Permission checks

Roles, permission overrides and explicit denies control access; a token proves identity, not authorization.

Private capabilities

Guest passes and invoices use narrow capability access and do not authorize staff or payment actions.

Outlet isolation

Orders, invoices, queue actions, payments and dashboards are checked against the assigned business and outlet.

Requires production/provider activation

Release gates still open

  • Mandatory login-email delivery provider, templates, retry handling and delivery verification
  • Firebase Identity Platform MFA enrollment, challenge and recovery
  • Distributed rate limiting across Cloud Run instances
  • Capability expiry/rotation and Firestore reservation reconciliation
  • Retention, redaction, backup and restore operations
  • External security review and pilot load/restore drills
  • Final production CORS, CSP, DNS and secret-management verification

No certification claims

No SOC, ISO, PCI or similar badge is claimed. Counter payments do not pass through QwikPass.

Login alert workflow

The application event and provider adapter exist locally. Actual mandatory email delivery is a production activation gate.

Restaurant payment boundary

QwikPass records staff confirmation for counter payments and does not independently verify receipt.

Review the controls together with the release gates.

Enterprise security and data requirements are scoped from deployed evidence, not from badges or generic promises.

Review Enterprise scope Open product overview