Skip to content
Platform & hardware

Security & data protection

Card data is never stored, backups are encrypted, and every security event is logged

Security permeates every feature. This consolidates the mechanisms and policies protecting store data, customer information, card data and system integrity. The till handles sensitive financial transactions and must meet PCI DSS for cards, protect personal data under Saudi and Omani regulation, and ensure only authorised people perform authorised actions.

What this covers

  • Authentication — staff sign in by PIN, the owner by password plus two-factor, with biometric unlock
  • Authorisation — role-based access control, with a manager PIN override for manager-level actions
  • Encryption at rest — the local database is encrypted, and credentials live in the operating system’s secure store
  • Encryption in transit — TLS 1.3 for all API communication, with certificate pinning
  • PCI DSS — card data is never stored; the payment SDK handles it in a compliant manner
  • Session management — timeouts, screen lock and shift-bound sessions
  • Audit trails — every security event is logged: login, logout, override, delete, settings change
  • Device security — device registration, remote-wipe capability and hardware identifiers
  • API security — rate limiting, token-based auth, request signing and input validation
  • Backup encryption with AES-256-GCM

Related features

All features
  • Roles & permissions

    190+ granular permissions — and lending one for an hour

    9 capabilitiesSee the detail

  • Backup & recovery

    A backup that verifies itself, a restore to any point, and a wizard for a new machine

    10 capabilitiesSee the detail

  • Saudi Arabia

    ZATCA Phase 2 e-invoicing

    Signing, clearance and reporting in full — and the signing keeps working when the line drops

    14 capabilitiesSee the detail

See it on your shop

Thirty minutes on your products, your tax setup and your hardware — not a slide deck.