Security
Security at CampusBite OS
This page is maintained by the CampusBite OS team to answer common security questions about the platform. It describes the controls we have enabled today — it is not an independent audit or certification.
Last updated: 3 August 2026
Access and authentication
- Every account signs in through the platform's managed authentication; passwords are never stored by the app itself.
- Access is role-based across Super Admin, Admin, Manager, Cashier, Kitchen, Partner, Student and Faculty.
- Roles are stored separately from user profiles and can only be changed by an administrator.
- Protected areas such as the kitchen display, admin tools and the AI assistant are gated by role, and the same check is repeated on the server, not just in the browser.
Data access rules
- Permissions are enforced in the database itself with row-level rules, so a request cannot bypass them by calling the API directly.
- Students and faculty can read their own profile; other users' profiles are not readable.
- Order lists, student names and signatures are readable only by authorised café staff.
- Guests tracking an order can only load that single order through its unique link, and sensitive fields are excluded from what is returned.
- The AI assistant endpoint requires an authenticated staff role and limits the size of each request.
Platform and hosting
CampusBite OS is built and hosted on Lovable Cloud. Traffic to the application is served over HTTPS, and the database, authentication and server functions are managed by the platform. Administrative keys are held server-side only and are never shipped to the browser.
Credit records and signatures
Credit purchases capture a digital signature at checkout and store it alongside the order so the café has a verifiable record. Signature data is treated as sensitive and is restricted to authorised staff.
Shared responsibility
- Lovable Cloud provides the hosting, database, authentication and infrastructure layer.
- The CampusBite OS team configures roles, access rules and application behaviour, and reviews them when features change.
- Your café or institution is responsible for granting staff roles carefully and removing access when people leave.
- You are responsible for keeping your own login credentials private.
Reporting a vulnerability
If you believe you have found a security issue, please email hello@campusbites.online with a description and the steps to reproduce it, and give us a reasonable opportunity to respond before sharing it publicly. Please do not access, modify or delete data that is not your own while testing.
Security contact
For anything urgent you can also reach us on 9663092227. We are based in Bangalore, Karnataka, India.
Contact us
Questions about this page, your data, or the platform? Reach the CampusBite OS team directly.