Your venue's data is mission-critical. We protect it with bank-grade encryption, Australian-only hosting, and a local-first architecture that keeps you running no matter what.
Data breaches since launch
Measured uptime, last 12 months
Encryption standard
Security monitoring
Every layer of Appetite is designed with security at its core, from hardware to cloud to the way your staff interacts with the system.
AES-256 at rest, TLS 1.3 in transit
Every byte of data is encrypted, whether it's sitting on your hardware or moving between your terminal and our cloud. We use the same encryption standards as major banks.
SOC 2 compliant data centres
All cloud data is stored in Australian-based data centres. Your venue data never leaves the country, ensuring full compliance with Australian data sovereignty requirements.
Works offline, syncs securely
Your POS runs on local hardware first. If the internet drops, your venue keeps operating. Data syncs via encrypted tunnels the moment connectivity is restored.
PCI-DSS Level 1 via Tyro
We never see, store, or process raw card data. All payments are handled by Tyro's PCI-DSS certified hardware using Point-to-Point Encryption (P2PE).
Local-first storage
Australian data centres
Credit card data never touches Appetite systems. All payment processing flows directly through Tyro's PCI-DSS Level 1 certified hardware using P2PE encryption.
Your data is stored locally on your POS hardware and synced to Australian-based cloud servers. We never store data outside of Australia.
No. We never see, store, or process raw cardholder data. All payment processing is handled by Tyro using PCI-DSS certified, Point-to-Point Encrypted hardware.
Your POS continues operating normally using local-first architecture. All transactions are processed locally and synced to our cloud via encrypted tunnels when connectivity is restored.
We have a documented incident response plan with defined escalation procedures. Affected customers are notified within 72 hours as required by the Notifiable Data Breaches scheme.
Yes. Upon account termination, you can request a full data export within 90 days. After that, personal data is permanently deleted from our cloud systems, except where retention is required by Australian tax law.
Switch to a POS that treats security as a feature, not an afterthought.