This policy document is a structured drafting placeholder established for architectural, regulatory, and UX integrity. It does not constitute final binding legal terms. Formal legal review and jurisdiction-specific counsel are required before official commercial deployment.
Food Tailor operates on modern cloud infrastructure utilizing microservices isolated within virtual private clouds. All external traffic is routed through Cloudflare edge defenses providing DDoS protection and Web Application Firewall (WAF) rule enforcement.
• In Transit: All client-to-server and inter-service communications enforce TLS 1.3 encryption with strict HTTP Strict Transport Security (HSTS) headers.
• At Rest: Database tables, token caches, and document stores are encrypted using industry-standard AES-256 keys managed via AWS Key Management Service (KMS).
Food Tailor never stores raw credit card numbers, CVVs, or bank account PINs on our servers. All financial transactions are tokenized and processed directly by our PCI-DSS Level 1 certified gateway partner, Razorpay.
Access to internal databases and administration tools requires multi-factor authentication (MFA) and strict role-based authorization. Administrative actions are immutably logged with request IDs and timestamps.