Security

Security controlsClear, verifiable protection

A practical view of the safeguards built into Wox, what our engineering team reviews, and the steps every customer should take to protect its workspace.

Platform safeguards

Protection is layered across every request.

No single control carries the whole system. Identity, tenant scope, permissions, request validation, and private file access work together before data reaches a user.

01

Tenant-scoped access

Authenticated requests resolve the user, organization, and location context so restaurant data is handled inside the correct workspace boundary.

02

Least-privilege permissions

Role, module, and component permissions limit which screens and protected actions each team member can use.

03

Request safeguards

Secure authentication, CSRF checks for cookie flows, rate limits, and browser security headers reduce common web attack paths.

04

Private file delivery

Protected uploads are not exposed as public objects. Authorized workflows use authenticated access or short-lived signed links.

Engineering review

What we examine

Security review follows the paths that can expose customer data or change operational state.

  • Sign-in, token, cookie, MFA, and recent-authentication flows
  • Organization and location boundaries on data reads and writes
  • Role and permission checks on sensitive screens and mutations
  • Private uploads, generated files, and time-limited download access

Shared responsibility

What workspace owners control

Wox protects the platform; your access decisions protect the workspace day to day.

  1. 1Require MFA or passkeys for owners, managers, and finance users.
  2. 2Give every person a named account instead of sharing credentials.
  3. 3Grant the smallest role and location scope needed for the job.
  4. 4Remove inactive members and review access after role or employment changes.

Security transparency

Need evidence for your review?

Security capabilities evolve with the product. Ask our team for current control details, architecture answers, or help completing a vendor security questionnaire. We will describe the controls that are in place without presenting planned certifications as completed work.

Ask a security question