QwikPass
Active controls and published gatesSecurity & access

Authorization follows the Organization, Outlet, role and explicit permission.

This page separates controls enforced in QwikPass today from work required for larger deployments. It is not a certification or compliance claim.

Enforced now

Identity alone never grants access to restaurant data.

Tenant context

Protected requests resolve the current Organization membership and authorized Outlet assignment.

Permission checks

Role defaults, permission overrides and explicit denies control access. A signed token proves identity—not authority.

Private capabilities

Guest passes and invoices use narrow, unguessable capability access and never authorize staff, plan or payment actions.

Outlet isolation

Orders, invoices, queues, payments, analytics and settings are checked against the assigned Business and Outlet.

Optional authenticator MFA

Verified staff can add a six-digit authenticator factor. Sensitive MFA changes require a recent sign-in.

Browser abuse controls

Firebase App Check protects browser mutations and direct realtime reads. Sensitive public and signed-in routes also use distributed application limits.

Recovery controls

Firestore point-in-time recovery, delete protection, seven-day daily backups and retryable notification recovery are enabled in production.

Published rollout gates

Controls still required before broader or custom claims

  • Production endpoint acceptance and monitored delivery callbacks for the approved WhatsApp invoice and order-update templates before managed WhatsApp is declared generally available
  • Staged reconnect, read-cost and load measurements before high-volume guest-pass listeners are enabled
  • Periodic capability rotation and historical reservation-reconciliation runbooks
  • A documented restore drill plus contracted retention and redaction procedures
  • External security review together with load, failover and restore drills before a high-profile enterprise rollout
  • Restaurant-specific invoice, tax and statutory review before each live merchant launch

No certification claims

No SOC, ISO, PCI or similar badge is claimed. Razorpay tokenizes payment details; QwikPass does not store PAN or CVV.

Mandatory login alerts

Every successful interactive staff login creates a durable security event and sends an email through the QwikPass transactional provider using the verified security@qwikpass.in identity.

Restaurant payment boundary

QwikPass records staff confirmation for counter payments. Connected restaurant accounts use Razorpay partner OAuth so online-order money settles directly to the restaurant.

Review the controls together with the release gates.

Enterprise security and data requirements are scoped from deployed evidence, not from badges or generic promises.

Review Enterprise scope Open product overview