Account and tenant controls
BMS uses authenticated sessions, organization-scoped database access rules, and role-based permissions for operational, team, settings, and billing actions.
Data and documents
Application traffic uses HTTPS in production. Uploaded invoice documents are stored in a private bucket and accessed through short-lived signed links. Database policies restrict records to the user's organization.
Operational safeguards
Sensitive server errors are not displayed to end users, important account and operational actions are recorded in an audit log, and uploaded files are restricted by type and size.
Report a concern
Please do not include passwords or sensitive restaurant data in an initial report. Use the contact form and we will coordinate a safe way to share details.