PILOT-STAGE SECURITY & DATA HANDLING
Least data.
Visible controls.
Control principles
- Least data: request only fields needed for the agreed analysis.
- Least privilege: prefer read-only, scoped exports or service accounts; never shared personal credentials.
- No card data: no payment-card numbers, CVV, track data, or other PCI authentication data.
- No unnecessary personal data: remove or tokenize employee and guest identifiers unless specifically required and approved.
- Human release gates: no automatic changes to purchasing, recipes, pricing, payroll, vendor records, or restaurant systems.
Transfer, storage, and isolation
Use client-controlled secure exchange, an approved data room, or encrypted files with the password transmitted separately. Store each client’s pilot data in a logically separated workspace, restrict access to assigned personnel, maintain an access inventory, and remove access when the pilot closes.
AI use
- AI may assist with field mapping, anomaly explanation, document summarization, and draft analysis.
- Deterministic calculations, reconciliations, and financial totals remain reproducible outside the model.
- Material findings require human review and Finance/Operations validation.
- Client data is sent only to approved providers under the client-approved configuration.
- Client-confidential data is not used to train public or cross-client models.
Retention and deletion
The default pilot target is deletion of client source data within 30 days after final acceptance unless the agreement requires a different period. Only the minimum engagement record needed for legal, billing, and agreed support obligations is retained.
Incident handling
- Contain the event and preserve relevant evidence.
- Notify the client’s named security contact without undue delay under the contract.
- Document affected systems, data categories, dates, and corrective actions.
- Revoke or rotate affected credentials and links.
- Complete a written post-incident review.
Certification status
MarginChef does not claim SOC 2, ISO 27001, PCI DSS, HIPAA, or another third-party certification unless and until that certification is actually obtained and can be evidenced. The 30-day pilot should be treated as a restricted, read-only analytics engagement with contract-specific controls.