Enterprise-Grade Security
Your business data deserves the highest level of protection. Sales Point 360 is built with security at every layer — from encrypted storage and tenant isolation to multi-factor authentication and real-time audit logging.
Your data is encrypted and isolated
Every tenant's data is completely isolated. No business ever sees another's information — guaranteed by architecture, not just policy.
Encryption at Rest
Sensitive settings are encrypted with AES-256-GCM authenticated encryption before storage. TOTP secrets use AES-256-CBC. Database credentials and JWT secrets are stored in environment files blocked from web access.
Encryption in Transit
All traffic is encrypted with TLS/SSL. API communications, webhook deliveries, and payment processing all happen over HTTPS — no exceptions.
Tenant Isolation
Every database query is scoped by tenant ID. Multi-tenant architecture ensures complete data isolation — each business operates in its own secure environment with zero cross-tenant data leaks.
Prepared Statements
All database queries use PDO prepared statements with emulated prepares disabled. SQL injection is prevented at the driver level, not just by input sanitization.
Secrets Management
Database credentials, JWT secrets, and encryption keys live in .env files blocked by server configuration. API keys are bcrypt-hashed before storage and masked in API responses.
Input Sanitization
Every user input is sanitized with trim and tag stripping. Error messages are scrubbed before reaching clients — stack traces and internal details stay server-side.
Multi-layered authentication
From password hashing to time-based one-time passwords, every authentication pathway is hardened against attack.
JWT Tokens
Stateless Bearer token authentication using Cryptographically signed authentication tokens. Tokens are validated on every state-changing API request.
Bcrypt Passwords
All passwords and PINs are hashed with bcrypt at cost factor 10. Plain-text credentials never touch the database.
TOTP 2FA
Time-based one-time passwords with secrets encrypted at rest using AES-256-CBC. Compatible with Google Authenticator, Authy, and any RFC 6238 TOTP app. Enforceable per-tenant, platform-wide, or for super admins.
Rate Limiting & Lockout
Login attempts are rate-limited with automatic account lockout after configurable failed attempts. PIN login has the same protection as email login.
94 permission modules for precise control
Define exactly who can see, create, edit, and delete across every part of the system. No more all-or-nothing access.
Granular Permissions
94 permission modules covering every feature — from products and sales to AI insights, fleet management, and franchise operations. Each module supports view, create, update, and delete actions independently.
7 Default Roles
Admin, Manager, Supervisor, Cashier, Inventory Clerk, Accountant, and Viewer — pre-configured for common team structures. Create custom roles to match your exact workflow.
Tenant Scoping
Every API request is scoped to the authenticated user's tenant. Super admins can operate across tenants, but regular users are strictly confined to their own business data.
UI Enforcement
The admin sidebar automatically hides menu items based on both role permissions and plan features. Direct URL access is blocked server-side — no client-only security.
Last-Admin Protection
The system prevents deletion or demotion of the last administrator, ensuring you can never lock yourself out of your own account.
Plan-Based Gating
Features are gated by subscription plan in addition to role permissions. Six plan tiers from Free to Enterprise control which modules are available to each tenant.
Hardened infrastructure
Multiple layers of protection between your data and the outside world.
Cloudflare CDN
Global CDN with DDoS protection, Web Application Firewall, and edge caching for fast, secure content delivery worldwide.
Hardened Server Stack
Nginx 1.29 with server tokens disabled, PHP 8.3 with FPM, and MariaDB with strict mode. SSH hardened with strong ciphers, limited auth tries, and secure configuration.
Security Headers
HSTS, Content Security Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy headers enforced on every response. No unsafe-eval in CSP.
API Rate Limiting
File-based rate limiting at 120 requests per minute for standard endpoints, with stricter limits for public booking (10/hr) and online orders (20/hr).
CORS Protection
Cross-origin requests are restricted to allowed origins with subdomain wildcards and tenant custom domains. Credentials are only sent for verified origins.
24-Hour Token Expiry
JWT tokens expire after 24 hours (configurable). Short-lived sessions reduce the window of exposure from stolen tokens.
Built for compliance
The tools and practices you need to meet regulatory requirements and maintain customer trust.
PCI DSS Alignment
Payment processing is handled through PCI-certified gateways — Stripe, PayPal, Square, WiPay, and First Atlantic Commerce. Card data never touches our servers. Tokenized saved payment methods ensure cardholder data stays with the processor.
GDPR Compliance
Cookie consent banners with accept/reject. Full tenant data export via backup API for data portability. Soft-delete architecture supports right to erasure. Customers can request their data, and businesses can fulfill requests with a single click.
HIPAA Considerations
While Sales Point 360 is not itself HIPAA-certified, our architecture supports healthcare-adjacent businesses: AES-256-GCM encryption at rest, complete tenant isolation, audit logging with IP tracking, role-based access, and 2FA enforcement provide a strong foundation for compliance.
Audit Logging
Every state-changing operation is logged with user, action, entity, IP address, and tenant context. Full activity trail for accountability, forensic analysis, and regulatory compliance.
Webhook Security
All webhook deliveries are signed with HMAC-SHA256. Secrets are masked in API responses and only shown in full at creation time. Auto-disabled after 10 consecutive failures.
Training & Maintenance
Sandboxed training mode lets staff practice without affecting real data. IP-whitelisted maintenance mode allows safe updates. Training sales are excluded from reports and clearly marked on receipts.
Report a vulnerability
We take security seriously and welcome responsible disclosure from the community.
Contact Our Security Team
If you discover a security vulnerability, please report it responsibly. Send details to [email protected] and we will respond within 48 hours. Please include steps to reproduce the issue and any relevant technical details.
[email protected]