Book a demo
Security & reliability

Financial data, treated like financial data

Margin holds your purchase history, vendor pricing and margin performance. Access is scoped by role, location and entity, and every change to a costed record is logged.

  • Role-based access down to location and entity
  • Encryption in transit and at rest
  • Immutable audit trail on cost-bearing records
Good morning, Alex
Downtown · Tue, Oct 10 · updated 2m ago
Last 30 days
Command barSearch or ask about costs…
⌘ K
Sales
$248k
+4.2%
Food cost
28.4%
−1.1 pts
Prime cost
57.1%
Variance
$12.5k
Needs review
Margin trendActual · Target
Value delivered$18,420 recovered · 37 actions closed
Needs attention
3 invoice exceptions
Airport count overdue
Ribeye price +11.4%
AI insight

Airport food cost is 3.2 points above group. Beef usage explains most of the gap.

01Controls

How access and data are protected

Access control

  • Roles per location and entity
  • Least-privilege defaults
  • Approval limits by role
  • Offboarding removes access immediately

Data integrity

  • Unit-of-measure health checks
  • Missing mapping alerts
  • Exception queues
  • Source-record traceability

Authentication

  • Password policy enforcement
  • Session controls and timeouts
  • Single sign-on for enterprise plans
  • Device-level session revocation

Encryption

  • TLS for all traffic
  • Encryption at rest
  • Isolated tenant data
  • Secrets managed outside application code

Audit trail

  • Who changed what, and when
  • Count, invoice and price history
  • Period locking after close
  • Exportable audit reports

Backups & recovery

  • Scheduled automated backups
  • Point-in-time restore capability
  • Documented recovery objectives
  • Regular restore verification

Operations

  • Monitored infrastructure
  • Staged release process
  • Incident response procedure
  • Status communication to admins
02For your IT review

Built to survive a procurement questionnaire

Multi-entity groups, franchise networks and lenders all ask the same questions. We answer them with documentation, not assurances.

  • Data processing and retention terms provided in writing
  • Named data location and hosting details on request
  • Sub-processor list available for review
  • Security questionnaire support during evaluation
03Questions

Common security questions

Who can see a location's costs?+

Only users assigned to that location, plus roles explicitly granted group-level visibility. Franchise entities are separated from one another by default.

Can a posted count be edited?+

Corrections are recorded as new, attributed entries rather than silent overwrites, and periods can be locked after close.

What happens to our data if we leave?+

You can export your operational and cost data, and deletion terms are set out in the agreement.

Do you support single sign-on?+

Yes, on enterprise plans. We'll confirm your identity provider during evaluation.