Last updated: 24 August 2026
Our security posture, hosting and data residency, sub-processors, incident response and insurance — written to answer a security questionnaire.
Download this page (Markdown)Draft for review. Items marked [CONFIRM] are unverified, and the insurance section describes cover that must be purchased before it can be stated as fact. See the notes at the end before publishing.
We would rather tell you the last two up front than have you find them in a questionnaire.
AtTable holds operational data for hospitality venues: menus, orders, table sessions, bookings, payments and refunds, stock and supplier records, and staff shift data. Personal data within that is mostly Guest contact details for bookings and delivery, and staff account records.
We do not hold card numbers, expiry dates or security codes. We do not hold staff bank details or payroll data.
Full detail of the categories is in Annex I of the Data Processing Agreement.
Where processing takes place outside the UK, we rely on UK adequacy regulations or the ICO's International Data Transfer Addendum, supported by a transfer risk assessment. The location and safeguard for every sub-processor is listed in Annex III of the DPA.
We are not able to offer UK-only or EU-only data residency as a contractual commitment today. If that is a hard requirement for you, tell us before you contract.
Multi-factor authentication is not currently available on staff accounts. It is on our roadmap. We will not tell a questionnaire otherwise.
Card details are entered into fields hosted and served by the payment provider — Stripe, Square or Clover online, or the physical terminal for card-present payments. Those fields sit in the provider's own frame and are not reachable by our application.
Our servers receive a provider-issued token and a transaction reference. No column for a card number, expiry date or security code exists anywhere in our database. Strong customer authentication challenges happen between the Guest's browser and the provider.
For online payments the venue is the merchant of record on its own connected account. Money settles to the venue. AtTable does not hold customer funds.
The effect is that cardholder data stays inside the payment provider's environment and our systems remain outside cardholder data scope. We do not hold a PCI DSS certification and do not claim one — if you need a formal scope determination, your acquirer issues it.
[CONFIRM — the pre-deployment checks are implemented but are not currently enforcing on every deployment path. Do not describe them as gating until that is fixed.]
An authorised security assessment of the platform was completed in August 2026, covering authorisation, tenancy isolation, database privileges and mail authentication.
It found genuine issues, including database-level permissions that were broader than intended. All findings were remediated and independently re-verified, and controls were added to the deployment process to catch the same class of defect in future.
Log review over the available window found no evidence that the issues had been exploited. We will not state more strongly than that: the log retention window did not cover the entire period, so absence of evidence is what we have, and we would rather say so than overstate it.
A summary of the assessment and the remediation is available under NDA. Email security@attable.io.
We publish the complete list, with location and safeguard, in Annex III of the Data Processing Agreement. It currently includes Supabase, Vercel, Railway, Stripe, SumUp, Square, Clover, Resend, Cloudinary, PostHog, Sentry, OpenAI, Anthropic, Google and Companies House.
Customers get 30 days' notice before we add or replace a sub-processor, with a right to object on reasonable data protection grounds.
Email security@attable.io. Tell us what you found, how to reproduce it, and how to reach you.
We will acknowledge within 2 business days, keep you updated, and will not pursue legal action against anyone who researches in good faith, avoids privacy violations and service degradation, and gives us reasonable time to fix the issue before disclosing it.
We do not currently run a paid bug bounty, but we will credit you if you would like us to.
We maintain a documented incident response process. Where a personal data breach affects a customer's data, we notify that customer without undue delay and within 48 hours of becoming aware, with the information they need for their own regulatory notification. Contractual detail is in clause 10 of the DPA.
Where we are the controller — our own account, billing and security data — we notify the ICO within 72 hours where the breach is likely to result in a risk to people's rights, and affected individuals where the risk is high.
We hold no third-party security certification at present. Specifically, we do not hold and do not claim ISO/IEC 27001, SOC 2 Type I or Type II, Cyber Essentials, Cyber Essentials Plus, or PCI DSS certification.
What we can give you instead: this page, a completed security questionnaire, the DPA with its full sub-processor list and technical measures, and the August 2026 assessment summary under NDA.
[CONFIRM — this section must not be published until the policies are bound. See the notes below.]
AtTable maintains cyber liability and professional indemnity insurance with a reputable insurer. Cover includes data breach response and notification costs, third-party liability for loss of data, business interruption arising from a security incident, and regulatory defence costs.
A certificate of insurance is available to customers on request from legal@attable.io. Insurance obligations are contractual for customers on a Master Service Agreement — see clause 10 of the MSA.