Skip to content
Security

Your trading records are the most sensitive data you have

Sales, margins, suppliers, staff pay and customer contacts all live in one place. Here is precisely how we protect them, including the parts we have not finished yet.

Encryption everywhere

TLS 1.3 for everything in transit and encryption at rest for stored data - including the local database on every till and phone.

Granular access control

Roles scoped by branch and module. A cashier sees the till; an accountant sees the ledger; nobody sees more than their job requires.

Tamper-evident audit trail

Every transaction, override, void, discount and adjustment is recorded against a user and a device, and cannot be quietly rewritten.

Device registration

New devices must be approved before they can trade. Lost hardware can be revoked and remotely wiped from the back office.

Backups you can restore

Automated encrypted backups with point-in-time recovery, and restore drills we actually run rather than merely document.

Data residency

Enterprise customers can pin data to a specific region, or run entirely on their own infrastructure where regulation requires it.

Least-privilege internally

Our staff do not browse customer data. Access to production is limited, justified, time-bound and logged.

Exit without friction

A complete structured export on request, at any time, in a documented format. It is a contractual right, not a favour.

Being straight with you

What we have not done yet

Security pages usually list only achievements. Here is the other half.

  • We do not hold SOC 2 Type II or ISO 27001 certification yet. Both are on the roadmap, and we will publish the date once it is real rather than aspirational.
  • Our public bug bounty programme is not open yet. Responsible disclosure by email is welcome in the meantime and we respond quickly.
  • Single sign-on and SCIM provisioning are Enterprise features currently in development rather than generally available.
  • Independent penetration testing is scheduled ahead of general availability; we will share a summary report with customers who ask.
Security FAQ

The questions auditors ask

Still unsure about something? Ask us directly - a person answers, usually the same day.

Not yet, and we would rather say so plainly than imply otherwise. We are an early-stage company building toward formal certification, and our controls are designed around those frameworks from the start. Enterprise customers can request our current security documentation and a detailed questionnaire response.

Ready to see your business on one screen?

The point of sale is free forever - unlimited registers, unlimited stores, no card required. Add the back office only when you actually need it.

No card required · Free forever · No commission on your sales · Your data stays yours