Skip to main content

Security Settings

Protect your restaurant, staff, and customer data. Manage all settings under Owner > Settings > Security (owner or admin role required).


User Access Controls

RolePOSReportsMenu EditStaff MgmtSettings
OwnerFullFullFullFullFull
ManagerFullFullFullFullLimited
Shift LeadFullView onlyLimitedView onlyNone
Server/CashierOrder entryNoneNoneNoneNone
KitchenKDS onlyNoneNoneNoneNone

Add or edit users under Security > Users. Assign role, locations, and PIN. Set an expiration date for temporary staff.

PIN and Login Settings

SettingDefaultRange
PIN length4-6 digitsConfigurable
PIN expiry90 days30-365 days
Failed attempts before lockout53-10
Lockout duration15 minutes5-60 min

Password Policies

For web portal and management app access: minimum 12 characters with uppercase, lowercase, number, and symbol. Passwords expire every 90 days and cannot reuse the last 5. MFA (TOTP or SMS) is required for owner and admin roles.


PCI Compliance

Restaurant Revolution is PCI DSS Level 1 certified. Payment data is encrypted end-to-end and never stored on your devices. Role-based access, network segmentation guidance, automated compliance scans, and annual penetration testing maintain compliance. View status under Security > PCI Compliance.


Camera Integration

Connect supported camera systems (Verkada, Rhombus, Avigilon) under Security > Cameras. Map cameras to POS stations and entry points. Void, refund, and cash drawer events are automatically tagged with camera timestamps for event correlation.


Audit Logs

Every significant action is recorded and retained for 2 years:

Event TypeExamples
AuthenticationLogin, logout, failed attempts, lockouts
TransactionsVoids, refunds, discounts, cash drops
ConfigurationMenu changes, price updates, role changes
Data accessReport exports, customer data views

Filter by date range, user, event type, or location under Security > Audit Logs. Export as CSV for external review.