Security

Security is
non-negotiable.

Your venue's data is mission-critical. We protect it with bank-grade encryption, Australian-only hosting, and a local-first architecture that keeps you running no matter what.

0

Data breaches since launch

99.97%

Measured uptime, last 12 months

AES-256

Encryption standard

24/7

Security monitoring

Our Approach

Four pillars of protection

Every layer of Appetite is designed with security at its core, from hardware to cloud to the way your staff interacts with the system.

Encryption

AES-256 at rest, TLS 1.3 in transit

Every byte of data is encrypted, whether it's sitting on your hardware or moving between your terminal and our cloud. We use the same encryption standards as major banks.

Australian Hosting

SOC 2 compliant data centres

All cloud data is stored in Australian-based data centres. Your venue data never leaves the country, ensuring full compliance with Australian data sovereignty requirements.

Local-First Architecture

Works offline, syncs securely

Your POS runs on local hardware first. If the internet drops, your venue keeps operating. Data syncs via encrypted tunnels the moment connectivity is restored.

Payment Isolation

PCI-DSS Level 1 via Tyro

We never see, store, or process raw card data. All payments are handled by Tyro's PCI-DSS certified hardware using Point-to-Point Encryption (P2PE).

Infrastructure

How your data flows

Your Terminal

Local-first storage

AES-256
TLS 1.3 Encrypted Tunnel

Appetite Cloud

Australian data centres

SOC 2

Payment data is fully isolated

Credit card data never touches Appetite systems. All payment processing flows directly through Tyro's PCI-DSS Level 1 certified hardware using P2PE encryption.

Practices

How we keep you safe

Access Controls

  • Role-based access for all staff
  • Multi-factor authentication for admin accounts
  • Granular permissions per terminal and feature
  • Session timeouts and automatic lockouts

Continuous Monitoring

  • 24/7 infrastructure monitoring
  • Real-time anomaly detection
  • Automated threat response
  • 99.97% measured uptime over the last 12 months

Auditing & Compliance

  • Regular third-party penetration testing
  • Quarterly vulnerability assessments
  • Complete audit trails for all data access
  • Australian Privacy Principles (APPs) compliant

People & Process

  • Background checks on all employees
  • Mandatory security training
  • Least-privilege access policy
  • Documented incident response procedures

FAQ

Common security questions

Where is my data stored?

Your data is stored locally on your POS hardware and synced to Australian-based cloud servers. We never store data outside of Australia.

Does Appetite store my customers' credit card numbers?

No. We never see, store, or process raw cardholder data. All payment processing is handled by Tyro using PCI-DSS certified, Point-to-Point Encrypted hardware.

What happens if the internet goes down?

Your POS continues operating normally using local-first architecture. All transactions are processed locally and synced to our cloud via encrypted tunnels when connectivity is restored.

How do you handle security incidents?

We have a documented incident response plan with defined escalation procedures. Affected customers are notified within 72 hours as required by the Notifiable Data Breaches scheme.

Can I request my data be deleted?

Yes. Upon account termination, you can request a full data export within 90 days. After that, personal data is permanently deleted from our cloud systems, except where retention is required by Australian tax law.

Your data deserves
better protection.

Switch to a POS that treats security as a feature, not an afterthought.

AES-256 Encryption
Australian Servers
PCI-DSS Compliant