Covey

Security Controls

Posted: July 29, 2026 - Effective: July 29, 2026 - Last updated: July 29, 2026 - Operated by Service Pricer LLC - Prior versions available on request

This page summarizes current Covey security controls. No system is perfectly secure, but these controls describe the operating posture.

Access controls

Owner dashboards require authenticated sessions. Founder tools use separate admin authorization. Regular restaurant sessions are scoped to their own restaurant.

Payment controls

Stripe-hosted setup handles card verification. Covey stores metadata such as customer/payment method IDs, not full card numbers.

Bot controls

Cloudflare Turnstile protects signup/login forms when configured. Cloudflare also provides hosting, TLS, and network security controls.

1. Tenant separation

Restaurant owner sessions are limited to that restaurant's records through session tokens, restaurant IDs, and server-side authorization checks.

2. OAuth and secrets

Google OAuth uses provider-hosted consent. API secrets, OAuth client secrets, Stripe keys, and service tokens are stored server-side as platform secrets, not in public pages.

3. Logging and monitoring

Covey may keep operational logs, delivery records, payment status, security events, and error diagnostics to maintain service, troubleshoot issues, detect abuse, and comply with legal obligations.

4. Incident response

If we identify a security incident affecting users, we will investigate, mitigate, rotate exposed credentials where appropriate, and notify affected users as required by law.

5. Customer responsibilities

Users must protect their accounts, limit team access, review connected services, use accurate customer consent, and report suspected unauthorized access promptly.

6. Report issues

Report suspected vulnerabilities or exposed credentials to austinsdoors1@gmail.com.