Home

Security Statement

Last updated: June 2026

This page summarizes how TapKio approaches security for restaurant kiosks operating in direct-payment configurations. Security is a shared responsibility between TapKio and the Restaurant.

1. Card Data

In direct-payment configurations such as Zelle, Cash App, Venmo, or supported local payment apps, no card number, PIN, or CVV is entered into TapKio. Because no card data is captured at the kiosk, Restaurants may reduce card-data handling compared with traditional card-based kiosks.

PCI DSS scope is determined by the Restaurant's overall payment setup, not by TapKio alone. Restaurants accepting cards through other systems remain responsible for PCI compliance for those systems.

2. Transport Security

Connections between the kiosk, the staff confirmation dashboard, and TapKio services use industry-standard transport encryption (HTTPS / TLS).

3. Data at Rest

Credentials and other sensitive configuration data are stored using industry-standard encryption. Backups are encrypted in transit and at rest.

4. Access Controls

Staff accounts on the confirmation dashboard support per-staff PINs and role-based permissions (cashier, manager, owner). TapKio uses least-privilege internal access, multi-factor authentication for administrative tools, and access logging for production systems.

5. Sub-processors and Hosting

TapKio runs on reputable cloud infrastructure and uses a limited set of sub-processors for hosting, error monitoring, analytics, and messaging. We require contractual commitments from these providers around confidentiality and data protection.

6. Logging and Monitoring

We log access to production systems, monitor for anomalies, and review logs as part of routine operations and incident response.

7. Vulnerability Management

We track dependencies, apply security updates on a risk-prioritized schedule, and use automated scanning tools as part of our development process.

8. Incident Response and Notification

We maintain an incident response process. In the event of a security incident affecting personal information processed on behalf of a Restaurant, we will notify the Restaurant without undue delay so the Restaurant can meet its own notification obligations under applicable law.

9. Restaurant Responsibility

Restaurants are responsible for: keeping account credentials, PINs, and recovery codes confidential; promptly removing former employees from the dashboard; training staff on the confirmation workflow and on payment-fraud red flags; securing the physical kiosk hardware and its network; keeping operating systems and other payment systems patched; and maintaining backups of their own business records.

10. Reporting a Vulnerability

Please report suspected security issues to the email hello@tapkio.com. We ask researchers to test only against systems they own or have permission to test, to avoid privacy or service disruption, and to give us a reasonable opportunity to investigate and remediate before public disclosure. Do not include sensitive personal data in initial reports.