Security

Security at Nordkestrel

An overview of the controls we have in place to protect your restaurant data, your diners' data, and the integrity of the platform.

Last updated: April 23, 2026

Infrastructure

Nordkestrel is hosted on Cloudflare. The stack runs globally at Cloudflare's edge — no self-managed servers, no private VPC to patch, no SSH keys lying around.

Data in transit

Data at rest

Authentication and authorization

Payments

Audit logging

Sensitive admin actions (staff changes, menu publishes, payout triggers, refunds, domain changes) are written to an immutable audit log tied to the restaurant. Logs are retained for 12 months.

Rate limiting and abuse protection

Secrets and keys

Data portability

Restaurants can export orders, customers, menus, and campaign data as CSV at any time from the dashboard. Full account deletion purges operational data within 30 days.

Reporting a vulnerability

If you believe you have found a security issue, please email our security contact. Include reproduction steps and a description of the impact. Please do not probe production systems for vulnerabilities beyond what is needed to demonstrate the issue, and do not access data that does not belong to you.

We commit to acknowledging reports within 3 business days and will credit researchers who responsibly disclose issues in our changelog.

Compliance

We're a small team building in public and have not yet pursued formal SOC 2 or ISO 27001 certification. Our controls are modeled on those frameworks, and we will seek certification as customer demand warrants.