Security Statement

This statement summarizes Pedestal's current security practices for Pedestal POS, Back Office, Online Ordering, Customer Display, Kitchen Display, and related websites and applications. It is reviewed at least annually and when material product, vendor, legal, infrastructure, or data-processing changes occur.

Security ownership

Pedestal Studios Inc. designates company leadership as responsible for information security, privacy coordination, vendor review, incident response coordination, and security policy review. As the company grows, Pedestal may assign additional internal personnel or third-party advisors to support these responsibilities.

Access controls and MFA

Pedestal requires multifactor authentication where available for company email, cloud providers, code repositories, deployment platforms, payment-related portals, and privileged administrative accounts. Access is limited based on business need and role.

Merchant staff access is controlled through authentication, role-based permissions, location scoping, and merchant data isolation. Customers are responsible for keeping their own user accounts, passwords, devices, and assigned roles current and secure.

Data protection

Pedestal uses HTTPS/TLS for data in transit where supported and relies on reputable cloud providers that encrypt hosted data at rest. Pedestal does not intentionally store full card numbers, CVV, PIN data, magnetic stripe data, or EMV authentication data. Payment authorization, approval, processing, settlement, and ACH services are handled by third-party processors, gateways, banks, or billing platforms.

Pedestal processes confidential customer information and personally identifiable information as needed to provide POS, ordering, reporting, customer, employee, inventory, support, and account-management services. Additional privacy details are in the Privacy Policy.

Device, endpoint, and network practices

Pedestal uses company-controlled devices and accounts for development, deployment, and support work. Company endpoints should maintain operating system security updates, antivirus/firewall protection where available, secure screen locking, and device encryption where supported. Remote access tools, if used, should require MFA or another strong authentication control.

Backups and continuity

Pedestal uses cloud infrastructure and application-level safeguards to support data continuity, including database backups or provider-managed recovery features where available. Pedestal POS also includes local/offline operation for supported stations so merchants may continue limited operations during some connectivity interruptions.

Incident response procedure

Pedestal maintains a practical incident response procedure for identifying, triaging, containing, investigating, remediating, and documenting suspected security or privacy incidents. When an incident may affect customer data or service availability, Pedestal will use reasonable efforts to notify affected customers consistent with applicable law, contractual obligations, and operational realities.

  1. Receive and log the suspected issue or alert.
  2. Assess severity, affected systems, data types, and customer impact.
  3. Contain the issue by revoking access, rotating credentials, disabling affected functions, or isolating systems as needed.
  4. Preserve relevant logs and evidence where reasonably available.
  5. Remediate the root cause and verify recovery.
  6. Notify affected customers, providers, or authorities where required.
  7. Document lessons learned and update controls where appropriate.

Funds-transfer and electronic payment validation

Pedestal validates SaaS billing and electronic payment requests before processing. Controls may include written customer authorization, matching invoices to customer records, using approved billing platforms, MFA on billing accounts, avoiding payment changes based only on email or text requests, and manually reviewing unusual or high-risk payment changes.

Customer responsibilities

Customers are responsible for maintaining secure networks, supported hardware, appropriate employee permissions, accurate product and tax configuration, processor and gateway reconciliation, payment terminal security, backup procedures for exported data, and prompt reporting of suspected unauthorized access or suspicious transactions.

Report a security issue

Security or privacy questions can be sent to support@pedestalpos.com. Please do not include full payment card data, CVV, PIN, passwords, or sensitive secrets in support messages.