Security & compliance

Payments stay with the payment experts

Tableside is designed so sensitive payment instruments are captured by PCI-compliant payment providers, not stored by Tableside.

No card-data custody

Tableside does not store raw card numbers, CVVs, or sensitive payment instruments on our systems.

PCI-compliant providers

Payment capture is handled by PCI-compliant providers such as Stripe or supported secure payment terminals.

Provider-hosted payment capture

Guests enter card details directly into the provider's secure environment or on certified payment hardware.

Operational security

Tableside uses secure application practices for restaurant operations data and avoids representing SOC 2 status unless an attestation applies.

PCI vs. SOC 2

PCI DSS is the relevant standard for payment card data. SOC 2 is a broader audit framework for operational security controls.

Tableside's payment architecture keeps raw cardholder data in the payment provider's secure environment. We do not claim SOC 2 certification for Tableside unless and until a current attestation is available.