Skip to content

Security and compliance

Your stock levels, your margins and your customer list sit in these systems. Here is how they are protected, and what we will sign before we see any of it.

Answers on the same working day. Built in Lahore.

Security is part of the build, not a phase

We design the permission model before we design the screens, because retrofitting one onto a live point of sale means downtime in the shop.

We are a small team, so we tell you plainly what we do and do not hold. We are not certified against SOC 2 or ISO 27001. We can build to those controls and we will say so in writing; we will not claim an audit we have never sat.

Four rules we hold to

Defence in depth
More than one layer has to fail before data is exposed.
Least privilege
Access to what the job needs, for as long as the job lasts.
Transparency
You can ask who touched your data and we will tell you.
Review
Every change is read by a second engineer before it ships.

What is switched on by default

Every deployment ships with these. None of them is an upgrade tier.

Encryption at rest

AES-256

Databases and backups are encrypted on disk, including the off-site copies.

Encryption in transit

TLS 1.3

Every connection between a till, a browser and the server is encrypted.

Access control

RBAC

Roles decide what a cashier, a manager and an owner can see. Our own access is separate and revocable.

Audit logging

Append-only

Logins, price edits, refunds and stock adjustments are written with the user and the timestamp.

Secure development

OWASP Top 10

Threat modelling before the build, code review before the merge, and no secrets in the repository.

Patching

Weekly

Dependencies are monitored for advisories and updated on a schedule, not when something breaks.

Where we can meet a regulator

Three areas clients ask about most, and what we actually deliver in each.

AreaWhat we doWhat it covers
GDPRWe build to GDPR requirements when your users are in the EU.
  • Data minimisation
  • Right to erasure
  • Data portability
  • Consent management
Data residencyYou pick where the data lives, and we deploy to that region.
  • EU data centres
  • US data centres
  • On-premise
  • Custom regions
Industry standardsWe work towards a specific standard when your contract requires one.
  • SOC 2 awareness
  • HIPAA considerations
  • PCI-DSS for payments
  • ISO 27001 practices

Paperwork we sign

All four are available on request. Ask for them before the first call and we will have them back to you within the same working day.

  1. 01

    Non-disclosure agreement (NDA)

    We sign before the first technical discussion. Yours or ours, whichever you prefer.

  2. 02

    Data processing agreement (DPA)

    For work touching personal data, covering us as processor and you as controller.

  3. 03

    Service level agreement (SLA)

    Written uptime and response targets, with what happens when we miss them.

  4. 04

    Source code escrow (Escrow)

    A third party holds the code so the system outlives the relationship.

Send us your security questionnaire.

We will fill it in and mark the rows we cannot answer yet rather than guessing. If your procurement team needs a call with an engineer, they get one.

Talk to us about security
First reply
same working day
Built in
Lahore, Pakistan
WhatsApp, any time+92 335-0706014