Security
Security is designed into the workflow.
SEZA combines access controls, role-based permissions, audit records, protected payment integrations and operational safeguards designed for a multi-tenant point-of-sale platform.
Encrypted connections
Production traffic is served over HTTPS/TLS so information is encrypted while moving between supported browsers, devices and SEZA services.
Least-privilege access
Merchant records are protected with database authorization rules. Employees receive access based on the store, role and permissions assigned to them.
Managed data platform
SEZA uses managed cloud database and application services with provider security controls, operational monitoring and backup capabilities configured for the deployed environment.
Separated surfaces
The public website, merchant dashboard, Android register and platform-admin workflows are separated and require the appropriate authentication and role.
Audit history
Sensitive operations - including refunds, voids, cash movements, permission changes and admin actions - can be recorded for review.
Stripe-hosted billing
SEZA Subscription card details are handled by Stripe. SEZA receives payment tokens and status information rather than storing full card numbers.
Merchant data boundaries
Products, sales, employees, customers and operational records are scoped to the relevant merchant and store. Application queries are expected to pass through authorization policies, while elevated platform operations require separate admin access and are subject to audit controls.
Incident response
When a security incident is confirmed, SEZA's priorities are to contain the issue, preserve evidence, restore safe service, assess affected data and notify customers or authorities when required by law. Report suspected issues to security@sezapos.com.
Responsible disclosure
Please send a clear reproduction to security@sezapos.com. Do not disrupt live stores, use social engineering, access more data than necessary to demonstrate the issue, or publish sensitive details before SEZA has a reasonable opportunity to investigate and remediate.
More detail?
Review the Trust Center and Legal Center for security, privacy and data-processing documentation.
