Security for POS, KDS, iFood/Rappi integration, own app and multi-unit operations.
Why now
Restaurants handle cards, courier data, customer addresses and inventory — in cheap systems integrated with iFood, Rappi, Anota Aí. Hacked menu, abused coupons, courier fraud, base leaks at service. Everything becomes the operator's problem, not the app's.
Applicable regulation
/attack-surface
Every engagement is designed for your environment. The points below are part of our standard playbook for this sector — final scope is adapted to your stack and contract.
Price manipulation, cancellation fraud, kitchen ticket integrity.
Menu sync, order manipulation, commission fraud.
Hacked QR Code, IDOR on order, coupon abuse and new-user farming.
Tokenization, cancellation, renewal fraud and card management.
Per-store segregation, manager access, royalty and marketing fees.
Geolocation, delivery-proof fraud, PII and phone exposure.
/methodology
Automated scanners find what's documented. Real attackers find what isn't. 90% of the work is manual — performed by specialists holding OSCP, CISSP, CRTO and GPEN.
Target mapping, OSINT, footprint, sector-specific threat modeling.
Deep enumeration, complementary scanning, manual exposure identification.
Manual validation with controlled PoC, finding chaining, escalation.
Executive + technical, step-by-step replication, mapped to applicable regulation.
/why-trust
Sector with fast tech adoption and almost no independent validation; focus on mid-size networks and franchises.
Technical assessment recognized in highly regulated, mission-critical environments — the pentest that finds what nobody had found before.
Douglas Lopes
Founder · CEO · intrus.io
/faq
Yes. We audit coupon logic, new-user abuse, cashback rackets and systematic farming.
Yes. Intrusive tests run in staging. Final validations happen in nighttime or dawn windows.
/contact
Schedule a confidential meeting. Within 48h we'll send a proposal with scope, timeline and pricing.