Home/Security
Security

How we protect your data

Where your data is stored, who can see it, and what we do to keep it safe.

Last updated 6 October 2026

01 Where your data is stored

MenuMap runs on Microsoft Azure. The MenuMap service stores your data in Azure data centres in the EU.

Vercel hosts the web app. Your browser gets your data straight from our API on Azure, so your data does not pass through Vercel.

02 A database of your own

Each company that uses MenuMap has a database of its own. Your files and your reps' current work sit in storage areas of their own, apart from other companies' data.

For signed-in users, every request is limited to their own company. Our server reads the company from the user's session, never from the request.

03 Your prices and volumes

From your order data we read only which products each of your customers ordered, and when. We do not read prices or quantities, so MenuMap does not hold them.

04 Encryption

Our web app and our API accept only HTTPS with TLS 1.2 or newer. Both tell browsers to use HTTPS only (HSTS).

Azure encrypts the data the MenuMap service stores on disk: the databases, the files, the saved copy of your reps' current work and the database backups.

05 Who can access your data

Only named MenuMap staff can access our production systems. If you ask for it, your own staff can read your own database. Our staff sign in to Microsoft Azure, GitHub and Vercel with multi-factor authentication.

Our API reaches the databases, the files and your reps' current work through Microsoft Entra managed identities.

Each user sees only their own company's data. Screens about a single customer show only the customers assigned to that user. Menu analyses of all your customers are visible to everyone at your company.

We limit how often anyone can try to sign in. Sessions use secure cookies that page scripts cannot read, and they end after 30 days at most. We can end any user's sessions at once.

06 AI and other services

The MenuMap service analyses your menus with AI models from Microsoft Azure OpenAI. No other AI provider is part of this analysis.

We store your data in the EU. Some analysis steps use Microsoft's global capacity. In Microsoft's words, such a request "may be processed in any geography where the relevant model sold by Azure is deployed". The other steps run in Microsoft's EU Data Zone.

Microsoft does not train its models on your data. Its terms say prompts and outputs "are NOT used to train any generative AI foundation models without your permission or instruction".

Microsoft may store prompts to detect abuse. Microsoft states that it keeps this data in our chosen geography. It also states that only its staff in the European Economic Area may review it.

The dictation buttons in text fields use your browser's own speech service, for example Google in Chrome, Microsoft in Edge and Apple in Safari. Reps who prefer not to use them can type instead.

07 Backups

For each customer under contract, we can restore its database to any point in the last 35 days. We also keep weekly copies for 8 weeks and monthly copies for 12 months, and Azure keeps the database backups in two regions.

For menus and analyses, we keep every earlier version of each file, on storage spread over several data centres.

08 How we build and run MenuMap

The store for your reps' current work saves to disk every second and keeps a standby copy, to protect it against a server failure.

Every change to the MenuMap app and API goes through a pull request. It must pass automated type checks, tests and lint before we can merge it.

GitHub Dependabot checks the libraries we use for known security flaws. The Semgrep code scanner checks every change to the MenuMap app, the API and the menu analysis.

Sign-in and every data request have a rate limit.

Automated alerts check for server errors every 15 minutes and notify us. Another check runs after every API deploy.

We keep our API logs for 90 days.

09 If something goes wrong

If a security incident affects your data, we tell you within 48 hours of finding it. We keep you updated until we close it.

10 Contact

Questions, or found a vulnerability? Write to security@menumap.ai.

MenuMap is a product of Enelyse Consulting Kft., Debrecen, Hungary.