Tenant context
Protected requests resolve the current Organization membership and authorized Outlet assignment.
This page separates controls enforced in QwikPass today from work required for larger deployments. It is not a certification or compliance claim.
Protected requests resolve the current Organization membership and authorized Outlet assignment.
Role defaults, permission overrides and explicit denies control access. A signed token proves identity—not authority.
Guest passes and invoices use narrow, unguessable capability access and never authorize staff, plan or payment actions.
Orders, invoices, queues, payments, analytics and settings are checked against the assigned Business and Outlet.
Verified staff can add a six-digit authenticator factor. Sensitive MFA changes require a recent sign-in.
Firebase App Check protects browser mutations and direct realtime reads. Sensitive public and signed-in routes also use distributed application limits.
Firestore point-in-time recovery, delete protection, seven-day daily backups and retryable notification recovery are enabled in production.
No SOC, ISO, PCI or similar badge is claimed. Razorpay tokenizes payment details; QwikPass does not store PAN or CVV.
Every successful interactive staff login creates a durable security event and sends an email through the QwikPass transactional provider using the verified security@qwikpass.in identity.
QwikPass records staff confirmation for counter payments. Connected restaurant accounts use Razorpay partner OAuth so online-order money settles directly to the restaurant.
Enterprise security and data requirements are scoped from deployed evidence, not from badges or generic promises.