Multi-tenant restaurant OS

Run the floor like the kitchen never blinks.

QR ordering, a display that glows when food is ready, a register that keeps working when the Wi‑Fi doesn't, and an end‑of‑day close that balances itself. Built for restaurants that run nights — not demos.

QAR‑nativeDoha‑builtOffline‑proofTenant‑isolated
Pass · Table 12
KDS

2×Lamb Mandi

extra rice · hot

FIRE
00:02

3×Chicken Shawarma

garlic · no pickles

ON PASS
00:11

1×Mixed Grill

rare steak

READY
00:24
Kitchen call realtime
QR orderingKitchen displayOffline cashierRecipe inventoryEnd-of-day closeWaiter fireSplit paymentsRealtime bellVoid approvalsTable managementQR orderingKitchen displayOffline cashierRecipe inventoryEnd-of-day closeWaiter fireSplit paymentsRealtime bellVoid approvalsTable management

The wedge

Four moves, one continuous thread.

We didn't bolt a POS onto a menu app. Ordering, cooking, paying and closing are a single pipeline — so a ticket fired at a table is the same object the kitchen bumps, the cashier settles, and the EOD reconciles.

01

The round trip, unbroken

Scan → order → fire → plate → pay → close. One order id travels the whole night; nothing is re-keyed, nothing is lost between the table and the pass.

A

Guest scans table QR

anon order, source=qr_code

B

Ticket hits the KDS

realtime, with a timer

C

Cashier settles

split cash / card / wallet

D

EOD balances itself

payments vs orders, logged

02

Works when the net doesn't

Friday 9pm, the router dies. The register keeps opening tickets, printing and taking cash on a local queue, then syncs the moment service comes back. Order ids are minted client‑side, so nothing collides.

offline writes, not just fallback
03

Recipes that survive reality

Sell a mandi, deduct its rice, lamb and ghee in base units. Sacks convert to grams, bottles to millilitres, and spoilage gets logged — so theoretical stock finally matches the shelf, and managers trust the numbers.

04

A bell the manager actually hears

The kitchen call pings the floor shell the instant a pass light turns green. WebSockets are reserved for the three screens that need them — KDS, waiter fire, the bell — while dashboards poll, so tenant #20 doesn't inherit a connection bill.

KDS · wsWaiter · wsBell · wsDashboard · pollManager · poll

Six seats at the table

Everyone logs in with a seven‑digit code.

No email soup, no shared logins. Each role lands on exactly the screens it needs — and Row Level Security makes sure a cashier's token can't even see another kitchen's data.

Owner

Own tenant · everything

Sees every screen, edits the public site and team, owns the close.

Routes to

/dashboard/menu/website-builder/team-pins/settings

Security you don't think about

Isolation isn't a feature we added. It's the floor.

CloudKitch is multi‑tenant from the first row. Every query a staff member runs is filtered by their own restaurant — enforced by Row Level Security, the last line of defence when everything else fails.

  • Postgres is the bouncer

    Tenant boundaries live in the database, not in your UI. Even a frontend bug can't cross kitchens.

  • Anon only where it's public

    Anonymous tokens can read an active menu and drop a QR order or a demo lead — nothing else.

  • Service role stays server-side

    The master key never ships to a browser. Onboarding and the print daemon are the only holders.

rls · tenant_data_all
create policy "tenant_data_all"
  on public.orders
  for all
  using (
    restaurant_id = get_user_restaurant_id()
    or is_platform_admin()
  );

-- a cashier's token can only ever see
-- orders where restaurant_id == theirs.
-- cross-tenant reads return zero rows,
-- at the database, before app code runs.

Live sandbox

Touch it. It's alive.

Fire an order and watch it land on the pass. Bump it through cooking to ready to served. This is the real interaction model of the KDS — running right here, in your browser.

simulated — nothing leaves this page

Pass · live2 tickets

2×Lamb Mandi

COOKING

1×Kunafa

READY

Book a demo

Bring us your night shift.

Tell us about your room and we'll set up a sandbox kitchen with your menu, then walk a full service together — fire, pass, pay, close. Thirty minutes, no slides.

  • We enter your menu for you (onboarding is paid, not homework)
  • Live in days, not quarters
  • Flat per‑location pricing in QAR — no commission maths

Sent straight to the platform console under RLS. We never sell your details.