Skip to main content
The Octane
Security

How we protect your data.

How The Octane stores, processes and protects your data.

Infrastructure

The Octane runs on Supabase (managed Postgres, Auth, Storage) with row-level security scoping every restaurant's data to its own organization. The database is hosted in Switzerland, in the Zurich region. The full list of companies that touch your data, with their purpose and location, is in the sub-processor annex.

Authentication

Sign in with an email magic link, a password or a passkey (WebAuthn). Two-factor authentication with a TOTP app is available, with single-use recovery codes for a lost phone. Passwords are never stored in plain text, and leaked-password detection blocks credentials known from public breaches. You can review your recent sign-ins and revoke any active session from your account.

Data access

Each organization's data is isolated by row-level security policies in Postgres, so the rule is enforced by the database and not only by the application. No user can read or write another organization's data. Four team roles (owner, manager, staff and viewer) set what each person may do, and custom roles can switch individual permissions OFF on top of a base role, never on: a role you hand out can never do more than you.

Traceability and retention

Sensitive actions are written to an append-only audit log, including anything an operator does while impersonating an account for support. Access logs and rate-limit records are purged on a schedule instead of growing forever. Deleting your account deactivates it at once and leaves a 14-day window to restore it before the data is removed for good.

Responsible disclosure

If you discover a security issue please email security@theoctane.ch. We aim to respond within 24 hours and will credit responsible reporters.

Start running your bar today.

Free until launch. Create your restaurant, add your products and your team, and close your first day.