Security
What protects your numbers.
Written from the code, not from a template. Everything on this page is something the software actually does, and the last group is the things we will not claim until they are true.
It only ever reads
Syphor cannot write to your point of saleThere is no path back. No code anywhere in Syphor opens a connection into a customer’s system. It cannot change a price, void a check, move a shift or touch a record. Data moves one way only.
Two ways in, and neither reaches into your restaurantIf your point of sale runs in your restaurant, it sends extracts out to us on a schedule. If it runs in your supplier’s cloud — Toast, Square, Clover, Oracle MICROS, Lightspeed, Revel — we read their interface, with your authorisation, which you can withdraw. Either way nothing is installed in your restaurant, nothing of ours opens a connection into your own system, and everything is read-only.
The answer engine can only run a readAnything that is not a single read query — an insert, an update, a delete, a change to a table, or two statements at once — is refused before it reaches the database.
And it is stopped after 30 secondsEvery query is killed at 30 seconds by the database itself, so no question can sit on your data.
Answers are cappedWhat comes back is capped at 200 rows.
How your numbers reach us
Encrypted the whole wayFiles arrive over SFTP, encrypted in transit, using the same transport as a secure shell.
Into a locked roomEach location gets its own account on our server, locked into its own drop folder. It cannot see another location’s folder, and it cannot see anything else on the machine — it has no shell at all, only file transfer.
Nothing is exposed to the internetThe database, the portal and the answer engine all listen on the machine itself only. One web server faces outward and nothing else does.
Where they are heldOn hardware we run, in a hosting center in North America. It is not on a shared platform belonging to anybody else.
Administrator accessShell access to the server is by key only — no password will open it.
Getting in
Passwords are never readableA password is stored only as a bcrypt hash. We cannot read yours, and neither can anyone who takes the file.
The sessionThe session cookie cannot be read by any script in the page, is marked secure in production, is not sent from another site, and ends when you close the browser.
Accounts are per personEveryone has their own login with a role on it. Nobody shares one.
What Syphor does not hold
No card dataNo card number, no expiry, no security code, no track data, no payment token. Not in any table — no column for one exists. Cards are held by a payment processor.
What it holds about your staff, and what it does notIt does hold named people. The employee file brings employee number, name, active flag, hire date and end date; the timecard file brings hours, pay rate, overtime, declared tips and credit card tips against that name. We say it here because it is the part a security page usually leaves out. What is never sent: no social security or insurance number, no home address, no personal telephone number, no personal email, no date of birth — no column for any of them exists. See the privacy notice, which says the same.
No guest names from the bookThe reservations feed is read-only, for reporting. It gives us covers, the time and the party size — not the guest’s name, not their telephone number, not their email, and not what they ordered last time. Syphor never writes to your book, never takes a booking and never cancels one. We read the book, not the guest.
No invoice imagesAn invoice you send is read, the figures are taken out, and the image is discarded. Only the extracted lines are kept.
No trackersNo analytics tracker, no advertising pixel, no session recorder and no third-party error reporting, in the product or on this website. Usage counts are written to our own database and go nowhere else.
What leaves, and who receives it
The model that writes your answersThe answer engine. A question sends the question, the map of your tables, and up to 200 rows of the result. An invoice sends the image. A morning brief sends the day’s figures and your logbook notes. This is the largest flow and we would rather you read it here than find it later.
A research serviceCompetitive research. Your restaurant’s name and address, and your competitors’ names. Never your sales, checks, labor, staff or guests.
An events serviceLocal events. A latitude, a longitude, a radius and a date range. Nothing that identifies you.
A weather serviceWeather. Coordinates and dates. No account and no name.
A mapping serviceTurns your address into coordinates. Receives your address.
Email and text deliveryDeliver the emails and texts you asked for — the recipient, and the message.
The full pictureWho holds what, for how long, and how to have it removed is on the Privacy page.
What we do not claim
No certifications, and we will not imply anySyphor has no SOC 2, no ISO 27001 and no penetration test certificate. We are a young company. When we have one it will be named on this page with its date, and not before.
We do not claim encryption at restData is encrypted in transit, on every hop that leaves our server. We are not going to tell you the disk is encrypted, because we have not done that yet.
We are not in scope for PCINot because we passed something — because we never touch card data. Our payment processor does.
Send us your questionnaireIf your security team has one, send it. We fill it in honestly, including the blanks, and you can decide with the real answers in front of you.
If something goes wrong
A figure that is wrongTell us. We find out why, we tell you what it should have been and what caused it, and we say whether any other morning was affected by the same thing. A number we got wrong is worth more to us than one we got right, and we would rather you heard it from us than found the second one yourself.
You hear inside 72 hoursIf your data is exposed we tell you inside 72 hours of knowing about it — what was involved, and what we did about it. Not a week later, and not in a footnote.
Tell us directlysecurity@syphor.com1 888 593 3881 Tell us what you found and how you found it. We will confirm we have it inside one working day, we will tell you what we did about it, and nobody who reports something in good faith will hear from a lawyer about it.
Two things to be straight about
Everything above was established by reading the software, line by line, by somebody told to assume the flattering answer was wrong. Where the answer was uncomfortable it is on this page anyway — the section on what leaves the building, and the section on what we do not claim.
This is a description of how Syphor works today, honestly given. It is not a warranty, and it is not an attorney’s document. What is contractually promised is whatever is written into a signed agreement.
Questions about any of it — 1 888 593 3881.