C cenaly.com
Start free

Trust

Security & data

Where your business data physically lives, who can see it and how that access is revoked. Only what works today — including an honest list of what is not there yet.

Where data lives

The cloud and region are set by the brand you signed up with. It is not an account setting and does not change on the fly.

Brand

cenaly.com, meni.ge

Cloud

AWS

Region

USA (us-east-1)

Account data, files and storefront delivery; site assets are served through a global CDN.

Brand

cenaly.ru

Cloud

Yandex Cloud

Region

Russia

A fully separate stack with its own sign-in: accounts are not created with the US identity provider.

Brand

Turkish brands

Cloud

AWS

Region

Germany (eu-central-1)

A regional copy of the stack closer to the market. To be clear: that is the EU, not hosting inside Turkey.

  • Accounts in different stacks are not linked: a cenaly.ru account and a cenaly.com account are separate, and moving between clouds means a new account plus a data import.
  • Some features work in one cloud only — the help article of each section says so.
  • Storefront files (menus, photos, public documents) are public on purpose: a guest’s browser opens them without signing in.

Protection in transit and at rest

HTTPS only

The site, the workspace, storefronts and the API run over HTTPS; http addresses redirect to https.

Encrypted storage

Buckets with account data are closed to public access and encrypted at rest by the storage (AES-256).

PINs are stored as hashes

A cashier PIN is stored on the server only as an irreversible hash; passwords are checked by the sign-in service and are not part of account data.

We do not store card numbers

Cards are processed by the payment provider; we only receive the result of the payment.

Two-factor sign-in

A code from an authenticator app when signing in to the web workspace — turn it on in Settings → Access.

Who has access

By default — only you. Every further level of access is granted by you and revoked by you.

Owner

Sees everything; the account moves to another owner only by an explicit transfer.

Staff by role

A role sets the sections and locations an employee sees; dismissal removes workspace access and revokes their phone extension.

Devices by code

A kitchen display or a monitor signs in with a code to a single page, without full access; the code is removed in one click.

Support — only with your consent

Only while the “Support access” switch is on and within the scope you chose; every session is logged, and revoking ends a session in progress.

Implementation partners — on request

Only on a request you approve, for a limited time and view-only by default; payments, staff permissions and exports are closed in any mode.

AI agents by API key

The key is shown once on creation and is revoked in the access settings.

Your data under your control

Full account export

One archive with settings, catalog, orders, customers and reviews. PINs, keys and passwords are deliberately left out.

Change history beta

Editors of key sections show who changed a record and when, what exactly changed, and let you roll a version back.

Account deletion

On request to support after an export; the request is fulfilled within 30 days of confirmation.

Guest data

A cookie banner with a consent log, a legal documents builder and a “My data” screen on the storefront — for your site and menu.

What is not there yet

We say it plainly so you can decide whether it fits your business.

  • We hold no security certifications (SOC 2, ISO 27001 or similar) and do not claim any.
  • There is no “restore the account to a date” button in the workspace and we do not publish internal backup retention — export before bulk changes.
  • Two-factor sign-in covers the web workspace only; mobile apps and Google sign-in do not ask for the code yet.
  • There is no log of which employee opened what; logs are kept for support and partner sessions.
  • There is no self-service portal for data subject requests (DSAR) — such requests are handled manually through export and the Customers and Staff sections.

Documents

Report a problem

A vulnerability in the platform

Write to a dedicated address, not general support. Include the page address and steps to reproduce; please do not publish details before we reply and do not download other people’s data.

security@cenaly.com

Illegal content on a client site

A complaint about a page or menu hosted on the platform.

File a report →

Suspected leak in your account

Change the password, revoke support access, device codes and API keys, then write to support.

Step-by-step guide → support@cenaly.com

Questions about your data?

Tell us about your business requirements — we will reply with what the platform covers today.

Contact us

Support: support@cenaly.com