Trust

Security at Garivio

You're trusting us with the data that runs your business. Here's how we approach protecting it — clearly, and without the buzzword soup.

Last updated: 13 July 2026

Security isn't a feature we bolt on — it's part of how the product is built. This page describes the practices we hold ourselves to. As we grow we'll deepen them, and we'll keep this page honest about where we are.

Encryption

Data is encrypted in transit using TLS (HTTPS) across our website, APIs and the realtime connections the apps depend on. Data is encrypted at rest in our managed infrastructure. Sensitive credentials and integration secrets are encrypted with dedicated keys rather than stored in plain text.

Access control

  • Tenant isolation. Every business's data is scoped to that business. Requests are checked against the tenant they belong to, on every call.
  • Roles & permissions. Within a business, staff get only the access their role needs — and sensitive actions (like reopening a settled check) can require a manager step-up.
  • Least privilege internally. Access to production systems is limited to the people who need it, and changes are logged.

Resilient by design

Garivio POS is built to keep working when the internet doesn't. Orders are captured on the device and queued locally, then synced safely once the connection returns — so an outage never means lost service or lost data. Conflicts are resolved deterministically rather than silently overwritten.

Backups & recovery

Production data is backed up regularly, and we test that it can actually be restored — a backup you can't restore isn't a backup. Our goal is to recover quickly with minimal data loss in the event of a failure.

Privacy & data protection

We address the Turkish Personal Data Protection Law (KVKK) and, where it applies, the EU General Data Protection Regulation (GDPR). We limit collection to defined purposes and do not sell personal data. Applicable access, correction, deletion and other data-subject rights are explained in our Privacy Policy.

Payments

This marketing site does not currently collect card details or complete paid card orders. After iyzico merchant activation, subscription card details will be entered into iyzico's secure payment flow rather than stored by Garivio.

Responsible disclosure

If you believe you've found a security vulnerability, we want to hear from you. Email security [at] garivio.com with the details and steps to reproduce. Please give us a reasonable chance to investigate and fix the issue before disclosing it publicly. We're grateful to researchers who help keep our customers safe.


Have a security or compliance question for a deal or review? Reach us at security [at] garivio.com or get in touch.