research
We Checked 40 Small-Business Software Platforms. None Explain How They Keep Your Data Separate From Everyone Else's.
By Octa Insights, Research Desk, Octabiz
· 7 min read

We checked 40 small-business software platforms. None explain how they keep your data separate from everyone else's.
Restaurants, hotels, shops, and home-service companies run their payments, customer records, and staff logins through third-party software: point-of-sale systems, booking platforms, and field-service tools. These systems are multi-tenant: the same software instance typically serves thousands of unrelated small businesses at once, meaning each vendor is trusted to keep one customer's payment and business data walled off from every other customer's.
We asked a narrow, checkable question: when a small-business owner looks at a vendor's own website, what does that vendor say, in its own words, on its own domain, about how it protects that data?
:::takeaways title="The short version"
- We read the security disclosures of 40 point-of-sale, booking, and field-service platforms across restaurants, hotels, retail, and home services.
- None of the 39 we could fully assess explain how they keep one customer's data separate from another's, despite all being multi-tenant systems.
- Fewer than half, 21 of 40, have a dedicated security page at all.
- Five vendors disclose nothing whatsoever, after a thorough search of their own sites.
- The FTC itself tells small businesses to monitor their software vendors' security, which is hard to do when vendors don't say much. :::
:::term word="tenant data isolation" How a piece of shared software keeps one customer's data separate from every other customer using the same system. Standard practice for any multi-tenant platform, but rarely discussed in public. :::
The headline number
Of the 39 vendors whose disclosures we could fully read, zero describe how they isolate one customer's data from another's, even though every one of them runs the same software for many unrelated small businesses at once.
:::stats title="What we found across 40 vendors"
- 0.0% | of the 39 assessable vendors describe tenant data isolation
- 52.5% | of all 40 vendors have a dedicated security page
- 67.5% | of all 40 vendors make some PCI/tokenization statement
- 27.5% | of all 40 vendors mention two-factor authentication :::
| Vertical | Vendors | Security page | States PCI | Encryption | Isolation | Names cert | States MFA |
|---|---|---|---|---|---|---|---|
| Restaurant | 10 | 4 | 7 | 7 | 0 | 4 | 2 |
| Hotel | 10 | 5 | 8 | 6 | 0 | 2 | 5 |
| Retail | 10 | 7 | 8 | 8 | 0 | 7 | 3 |
| Home services | 10 | 5 | 4 | 5 | 0 | 3 | 1 |
| All 40 | 40 | 21 | 27 | 26 | 0 | 16 | 11 |
:::chart type="bar" title="Disclosure rate by criterion, all 40 vendors" label="Chart" caption="Share of vendors making a specific, checkable claim on each measure." source="Octabiz vendor security review, 40 vendors, 2026"
- States PCI/tokenization | 67.5% | 27 of 40
- Encryption | 65.0% | 26 of 40
- Dedicated security page | 52.5% | 21 of 40
- Names a certification | 40.0% | 16 of 40
- Two-factor authentication | 27.5% | 11 of 40
- Tenant data isolation | 0.0% | 0 of 40 :::
:::chart type="donut" title="Do vendors even have a security page?" label="Chart" caption="21 of the 40 vendors studied have a genuine, dedicated security or trust page. The rest have scattered mentions or nothing."
- Has a dedicated security page | 21 | vendors
- No dedicated page found | 19 | vendors :::
The best and worst performers
No vendor in the sample disclosed everything, and five disclosed nothing at all.
| Category | Vendors | What they disclosed |
|---|---|---|
| Weakest disclosure | TouchBistro, NCR Voyix (Aloha), Frontdesk Anywhere, Service Fusion, FieldEdge | Nothing across all five criteria measured, after a thorough search of their own sites |
| Strongest disclosure | Square for Retail, Mews | 4 of the 5 criteria, the ceiling in this study. In both cases, the missing criterion was the same one every vendor missed: tenant data isolation |
:::warning title="A notable reversal, caught during review" Service Fusion's only public PCI-related content places compliance responsibility on the customer, not on Service Fusion itself. That's the opposite of a vendor disclosure, so it's scored as not disclosing PCI compliance. :::
:::quote author="Service Fusion" role="Payments help-center article" As a Service Fusion Payments customer, you are responsible for securely storing, processing, and transmitting cardholder data. :::
Why nobody is talking about data isolation
Every vendor in this study runs the same core software for many unrelated businesses at once. That's what makes SaaS pricing work. It also means a vendor's data-isolation model is one of the more consequential things it could disclose, since a flaw there doesn't just affect one customer, it potentially affects every business on that platform. And yet it was the one thing not a single vendor, however otherwise transparent, chose to explain.
The FTC's own guidance for small businesses puts the responsibility back on the owner:
:::quote author="Federal Trade Commission" role="Cybersecurity for Small Business guidance" Your business vendors may have access to sensitive information about your business or customers. Make sure they secure their own computers and networks. :::
That's sound advice that's difficult to act on when the vendor's own website gives you nothing to check it against.
:::note title="What this study does and doesn't show" This measures public disclosure, not verified security architecture. A vendor could have excellent data isolation and simply not publish details about it, or could publish claims we didn't independently test against its real infrastructure. What we can say is narrower and still useful: most of this software doesn't give an owner anything to evaluate on this specific point. :::
Where Octabiz stands on this
We built this study in part by holding ourselves to the same five questions. Octabiz enforces tenant data separation at the database level: every business's records are scoped by row-level security policies, not just application logic. We never store raw card numbers either; payments run through tokenized processor integrations instead, which limits what a breach could expose. Sensitive fields like contractor tax IDs are encrypted before they're ever written to disk, and financial actions like linking a bank account require a fresh two-factor code even for an already-logged-in user. We're not claiming to be the only vendor doing this. We simply think vendors, us included, should be judged on whether we say so clearly, not just on whether we do it.
:::steps title="What to ask your software vendor this week"
- Ask about isolation directly | "How is my business's data kept separate from your other customers'?" is a fair question, and per this study, one almost no vendor answers unprompted.
- Look for a named certification | SOC 2 Type II, ISO 27001, or a PCI attestation is a stronger signal than "we take security seriously."
- Check for two-factor authentication | Only 11 of the 40 vendors we reviewed mention it. If it's missing, ask why.
- Ask what happens in a breach | A vendor that has thought about tenant isolation usually has a clear answer here; one that hasn't, usually doesn't. :::
How we ran this study
We identified 40 point-of-sale, property-management, and field-service software vendors, 10 each serving restaurants, hotels, retail, and home-service businesses, and read each vendor's own security/trust page, or where none existed, its privacy policy, terms of service, and support articles. Each vendor was scored on five specific, checkable disclosures: PCI/tokenization, encryption, tenant data isolation, named certifications, and multi-factor authentication. A claim only counted if it was specific: generic language like "security is our top priority" did not qualify. We collected and adversarially reviewed the data in August 2026.
:::note title="One correction made during review" A vendor's certification claim ("completed independent third-party assessments") was initially scored as naming a certification. On review it names no specific standard or audit body. Every other vendor scored true on that criterion named SOC 2, ISO 27001, or a specific PCI attestation, so this one was downgraded. :::
:::warning title="Known limits" This measures disclosure, not practice, and two vendors' content could not be fully verified: one vendor's security page was inaccessible (JS-rendered) and is excluded from all counts rather than assumed to say nothing; another vendor's support content required cached search snippets due to a rendering error. Some vendors under shared corporate ownership were scored using a parent company's trust-center content. A small number of cited certifications apply to a vendor's hosting infrastructure rather than an independent audit of the vendor's own application. :::
:::cta title="See how Octabiz handles this" href="/" label="Explore Octabiz" Row-level tenant isolation, tokenized payments, and encrypted sensitive fields: built in, not bolted on. :::
:::faq
What counted as disclosing something?
A specific, checkable claim on the vendor's own site: a named certification, a stated encryption method, a described isolation model. Generic marketing language like "security is our top priority" did not count.
Does this mean these vendors have bad security?
Not necessarily. This study measures what vendors say publicly, not their actual architecture. A vendor could have strong protections and simply not publish details about them.
Which vendor disclosed the most?
Square for Retail and Mews each met 4 of the 5 criteria measured, the highest in the study. Neither disclosed tenant data isolation, the one criterion no vendor in the sample met.
Where can I get the underlying data?
Email insights@octabiz.ai for the full 40-vendor dataset, including every page read and the exact quote behind each score. :::
References
- Cybersecurity for Small Business: Federal Trade Commission
Full methodology, raw dataset, and per-vendor quotes available on request at insights@octabiz.ai.