Skip to content
Queux

Security & privacy

Operational data deserves deliberate boundaries.

Queux is designed around explicit tenant scope, minimum necessary personal information, private document handling and accountable history.

Illustration of a protected operational record and review trail

Security principles

Boundaries that follow the organisation and site.

Security is not a badge or a single setting. These are the design controls Queux applies across protected workflows.

Tenant-scoped retrieval

Protected resources are retrieved within their organisation and site context, not trusted from a selected-site screen value alone.

Policy checks

Authorisation verifies the person’s role and the resource scope. Cross-tenant lookups avoid revealing another tenant’s records.

Private files

Uploads are intended for private storage with validated type, generated names, malware-scanning boundaries and authorised streaming.

Accountable history

Published content and finalised submissions are immutable; corrections create versions or amendments with actor, time and reason.

Protected integrations

Recoverable credentials are encrypted, one-way secrets are hashed and webhook signatures are checked before persistence.

Data minimisation

Kitchen calculations use aggregate room, meal, dietary and texture counts by default, reducing unnecessary personal information.

Access model

The selected site is context, not permission.

Every protected action needs an authorised user and a resource verified within the appropriate organisation and site.

Role-aware access

Owners, administrators, kitchen staff, reviewers and auditors receive only the capabilities assigned to their work.

Non-disclosing lookups

Cross-tenant identifiers return a not-found response where disclosure itself would expose information.

Session controls

Authentication, verification, rate limits and session protections surround sensitive entry points.

Audit context

Critical changes record who acted, when, where and why.

Uploads stay away from public paths.

Private plans, certificates and evidence should be stored outside the public disk. The upload flow validates extension, detected MIME type and size, uses server-generated names, and passes content through the configured malware-scanning adapter.

A download is streamed only after the current user and tenant scope are authorised.

External boundaries stay explicit.

Provider and payment integrations use maintained adapters so signature checks, timeouts, retries, idempotency and logging can be tested without placing credentials in presentation code.

Queux does not store payment-card details. Payment processing depends on the configured payment provider.

Privacy posture

Collect what the kitchen needs — and explain why.

The intended privacy approach is purpose limitation, minimum necessary data, controlled access and documented retention.

The public privacy policy draft and data processing terms draft describe the intended framework. Both require qualified legal review before commercial launch.

Need a deeper review?

Bring your security, privacy or procurement questions.

Contact Queux