Your trading records are the most sensitive data you have
Sales, margins, suppliers, staff pay and customer contacts all live in one place. Here is precisely how we protect them, including the parts we have not finished yet.
Encryption everywhere
TLS 1.3 for everything in transit and encryption at rest for stored data - including the local database on every till and phone.
Granular access control
Roles scoped by branch and module. A cashier sees the till; an accountant sees the ledger; nobody sees more than their job requires.
Tamper-evident audit trail
Every transaction, override, void, discount and adjustment is recorded against a user and a device, and cannot be quietly rewritten.
Device registration
New devices must be approved before they can trade. Lost hardware can be revoked and remotely wiped from the back office.
Backups you can restore
Automated encrypted backups with point-in-time recovery, and restore drills we actually run rather than merely document.
Data residency
Enterprise customers can pin data to a specific region, or run entirely on their own infrastructure where regulation requires it.
Least-privilege internally
Our staff do not browse customer data. Access to production is limited, justified, time-bound and logged.
Exit without friction
A complete structured export on request, at any time, in a documented format. It is a contractual right, not a favour.
What we have not done yet
Security pages usually list only achievements. Here is the other half.
- We do not hold SOC 2 Type II or ISO 27001 certification yet. Both are on the roadmap, and we will publish the date once it is real rather than aspirational.
- Our public bug bounty programme is not open yet. Responsible disclosure by email is welcome in the meantime and we respond quickly.
- Single sign-on and SCIM provisioning are Enterprise features currently in development rather than generally available.
- Independent penetration testing is scheduled ahead of general availability; we will share a summary report with customers who ask.
The questions auditors ask
Still unsure about something? Ask us directly - a person answers, usually the same day.
Not yet, and we would rather say so plainly than imply otherwise. We are an early-stage company building toward formal certification, and our controls are designed around those frameworks from the start. Enterprise customers can request our current security documentation and a detailed questionnaire response.
Related reading: Privacy policy · Terms & conditions · Service level agreement
Ready to see your business on one screen?
The point of sale is free forever - unlimited registers, unlimited stores, no card required. Add the back office only when you actually need it.
No card required · Free forever · No commission on your sales · Your data stays yours