QX Security

Restaurant data,
bank-grade standards.

QX is built for the same auditors that review your payments. Encryption, permissions and immutable audit logs are the defaults — not add-ons.

99.99%
Uptime SLA
PCI-DSS
Payments
AES-256
Encryption
KSA-native
Data residency
Security pillars

Defence in depth, from the guest QR to the audit log.

PCI Compliance

Payment flows use certified acquirers and tokenized card data. Cardholder data never touches QX servers.

Encryption

TLS 1.2+ in transit, AES-256 at rest. Secrets managed in an isolated vault with automatic rotation.

Permissions & RBAC

Fine-grained roles for owners, managers, cashiers and auditors — enforced at the row and column level.

Audit Logs

Immutable event log for every sensitive action: pricing, refunds, permission changes and exports.

Privacy

Guests are stored under phone-hashed identifiers. Personal data is minimized, exportable and deletable on request.

Infrastructure

Isolated tenant environments, hardened base images, private networking and least-privilege service accounts.

Reliability

99.99% platform SLA, multi-AZ failover, live status page and 24/7 on-call for P1 incidents.

Data Residency

KSA-native storage for tenants that require it. Regional replicas for latency-sensitive branches.

Trust artefacts

Documentation your CISO will actually read.

Under NDA we share our architecture overview, controls matrix, pen-test summary and incident-response playbook.

  • Architecture & data-flow diagrams
  • Controls matrix mapped to ISO 27001
  • Annual third-party penetration test summary
  • Incident response and breach-notification policy
  • Sub-processor list and DPA templates
Live · qxpayment.status
All systems operational
Guest QR
99.99%
Payments
99.99%
Merchant Console
99.98%
API
99.99%

Need a deeper security review?

Our security team will walk your CISO or auditors through architecture, controls and incident playbooks — on your calendar.