01
Tenant-scoped access
Authenticated requests resolve the user, organization, and location context so restaurant data is handled inside the correct workspace boundary.
Security
A practical view of the safeguards built into Wox, what our engineering team reviews, and the steps every customer should take to protect its workspace.

Platform safeguards
No single control carries the whole system. Identity, tenant scope, permissions, request validation, and private file access work together before data reaches a user.
01
Authenticated requests resolve the user, organization, and location context so restaurant data is handled inside the correct workspace boundary.
02
Role, module, and component permissions limit which screens and protected actions each team member can use.
03
Secure authentication, CSRF checks for cookie flows, rate limits, and browser security headers reduce common web attack paths.
04
Protected uploads are not exposed as public objects. Authorized workflows use authenticated access or short-lived signed links.
Engineering review
Security review follows the paths that can expose customer data or change operational state.
Shared responsibility
Wox protects the platform; your access decisions protect the workspace day to day.
Security transparency
Security capabilities evolve with the product. Ask our team for current control details, architecture answers, or help completing a vendor security questionnaire. We will describe the controls that are in place without presenting planned certifications as completed work.