Trust and security

Your kitchen data, secure and in Europe

iResto runs on European infrastructure, is managed by We Enable and is built for organisations with multiple locations. Here you can read how we handle your data.

Hosting in the EU

All environments and backups are hosted by European providers in European data centres. No transfer outside the EU for processing your data.

GDPR-proof

A data processing agreement with every contract, data minimisation by design and a privacy statement that describes what we do and do not record.

Tenant isolation

Every organisation works in its own, separated environment. Locations within an organisation share central recipes, but never data with other customers.

Pentests and updates

Periodic external penetration tests on platform and API, a fixed release cadence and fast patching of dependencies.

Access and roles

Roles per function, from F&B director to kitchen staff, shared tablets with PIN code and single sign-on on request.

Backups and recovery

Daily backups with retention, recovery tests and a continuity plan. Registrations in the Kitchen App also work offline and synchronise afterwards.

API for developers

Open where it should be, closed where it must be

iResto has a public API with OAuth2 and webhooks, the same integration layer our own connections with wholesalers, POS systems and PMS use. It lets you connect iResto to your accounting, data warehouse or own tooling.

Questions about security or privacy?

Send us your questionnaire or book a call with our team. We answer security questionnaires within five working days.