Tenant isolation
Customer records are scoped by company and, where relevant, by branch. Platform and support access uses separate protected routes and must be audited.
Security and trust
Complytio is designed for UK hospitality teams handling staff activity, food-safety checks, EHO evidence, documents and billing data.
Customer records are scoped by company and, where relevant, by branch. Platform and support access uses separate protected routes and must be audited.
Document storage is designed around private Cloudflare R2 objects, tenant-scoped keys, signed access and optional app-level encryption for sensitive categories.
Restaurant owners, managers, staff, accountants, support agents and platform admins should receive only the permissions their work requires.
Platform and support accounts require two-factor authentication. Restaurant accounts can enable 2FA, with reminders and step-up checks planned for sensitive actions.
Support tools are diagnostics-first. Viewing documents requires a reason and audit trail instead of silent unrestricted impersonation.
Complytio uses Stripe-hosted Checkout and Customer Portal flows for paid subscriptions. Raw card data is never stored in Complytio.
Audit-first operations
Compliance software needs accountability. Complytio treats sensitive support, document, billing and evidence actions as auditable events.
The AI assistant is available to logged-in users with the right permissions. It searches published knowledge-base articles first, respects tenant and branch access, avoids support internal notes, and can escalate to a support ticket when unsure. Document text search in AI responses is on the roadmap.