Security

Security is designed into the workflow.

SEZA combines access controls, role-based permissions, audit records, protected payment integrations and operational safeguards designed for a multi-tenant point-of-sale platform.

Encrypted connections

Production traffic is served over HTTPS/TLS so information is encrypted while moving between supported browsers, devices and SEZA services.

Least-privilege access

Merchant records are protected with database authorization rules. Employees receive access based on the store, role and permissions assigned to them.

Managed data platform

SEZA uses managed cloud database and application services with provider security controls, operational monitoring and backup capabilities configured for the deployed environment.

Separated surfaces

The public website, merchant dashboard, Android register and platform-admin workflows are separated and require the appropriate authentication and role.

Audit history

Sensitive operations - including refunds, voids, cash movements, permission changes and admin actions - can be recorded for review.

Stripe-hosted billing

SEZA Subscription card details are handled by Stripe. SEZA receives payment tokens and status information rather than storing full card numbers.

Merchant data boundaries

Products, sales, employees, customers and operational records are scoped to the relevant merchant and store. Application queries are expected to pass through authorization policies, while elevated platform operations require separate admin access and are subject to audit controls.

Incident response

When a security incident is confirmed, SEZA's priorities are to contain the issue, preserve evidence, restore safe service, assess affected data and notify customers or authorities when required by law. Report suspected issues to security@sezapos.com.

Responsible disclosure

Please send a clear reproduction to security@sezapos.com. Do not disrupt live stores, use social engineering, access more data than necessary to demonstrate the issue, or publish sensitive details before SEZA has a reasonable opportunity to investigate and remediate.

More detail?

Review the Trust Center and Legal Center for security, privacy and data-processing documentation.