Security
Current controls, stated plainly.
This page describes controls verified in the current ACC implementation. It is not a certification, audit report, or guarantee that incidents cannot occur.
Restaurant access
The restaurant dashboard requires authenticated access. Login attempts are rate-limited, stored passwords are hashed, and successful sessions use signed access tokens. Restaurants are responsible for protecting their credentials and reporting suspected unauthorized access.
Restaurant data boundaries
Customer and operational routes use the authenticated restaurant identifier when reading or changing records. Sensitive customer actions fail when the requested record is not linked to that restaurant.
Messaging and voice media
Incoming Meta webhook signatures are checked against configured app secrets. Original WhatsApp voice media is not exposed as a provider URL in the browser. Customer Support requests it through an authenticated, restaurant-scoped backend proxy, which returns it for inline playback with private caching and content-type protections.
The AI receives a transcript for processing voice requests. Customer Support displays the original playable voice message, not that transcript.
Public website measurement
The public measurement endpoint accepts only same-origin, allowlisted event data with strict size and format checks. It does not add contact details, message content, IP addresses, or full browser user-agent strings to ACC’s custom analytics rows.
Reporting a concern
Send security and support reports to bakerjammoil@gmail.com. Include what happened, when it happened, and the affected restaurant or page. Do not email passwords, access tokens, or customer message contents.