Skip to main content
Security & Compliance

Enterprise-Grade Security

Your business data deserves the highest level of protection. Sales Point 360 is built with security at every layer — from encrypted storage and tenant isolation to multi-factor authentication and real-time audit logging.

Data Protection

Your data is encrypted and isolated

Every tenant's data is completely isolated. No business ever sees another's information — guaranteed by architecture, not just policy.

Encryption at Rest

Sensitive settings are encrypted with AES-256-GCM authenticated encryption before storage. TOTP secrets use AES-256-CBC. Database credentials and JWT secrets are stored in environment files blocked from web access.

Encryption in Transit

All traffic is encrypted with TLS/SSL. API communications, webhook deliveries, and payment processing all happen over HTTPS — no exceptions.

Tenant Isolation

Every database query is scoped by tenant ID. Multi-tenant architecture ensures complete data isolation — each business operates in its own secure environment with zero cross-tenant data leaks.

Prepared Statements

All database queries use PDO prepared statements with emulated prepares disabled. SQL injection is prevented at the driver level, not just by input sanitization.

Secrets Management

Database credentials, JWT secrets, and encryption keys live in .env files blocked by server configuration. API keys are bcrypt-hashed before storage and masked in API responses.

Input Sanitization

Every user input is sanitized with trim and tag stripping. Error messages are scrubbed before reaching clients — stack traces and internal details stay server-side.

Authentication

Multi-layered authentication

From password hashing to time-based one-time passwords, every authentication pathway is hardened against attack.

JWT Tokens

Stateless Bearer token authentication using Cryptographically signed authentication tokens. Tokens are validated on every state-changing API request.

Bcrypt Passwords

All passwords and PINs are hashed with bcrypt at cost factor 10. Plain-text credentials never touch the database.

TOTP 2FA

Time-based one-time passwords with secrets encrypted at rest using AES-256-CBC. Compatible with Google Authenticator, Authy, and any RFC 6238 TOTP app. Enforceable per-tenant, platform-wide, or for super admins.

Rate Limiting & Lockout

Login attempts are rate-limited with automatic account lockout after configurable failed attempts. PIN login has the same protection as email login.

Access Control

94 permission modules for precise control

Define exactly who can see, create, edit, and delete across every part of the system. No more all-or-nothing access.

Granular Permissions

94 permission modules covering every feature — from products and sales to AI insights, fleet management, and franchise operations. Each module supports view, create, update, and delete actions independently.

7 Default Roles

Admin, Manager, Supervisor, Cashier, Inventory Clerk, Accountant, and Viewer — pre-configured for common team structures. Create custom roles to match your exact workflow.

Tenant Scoping

Every API request is scoped to the authenticated user's tenant. Super admins can operate across tenants, but regular users are strictly confined to their own business data.

UI Enforcement

The admin sidebar automatically hides menu items based on both role permissions and plan features. Direct URL access is blocked server-side — no client-only security.

Last-Admin Protection

The system prevents deletion or demotion of the last administrator, ensuring you can never lock yourself out of your own account.

Plan-Based Gating

Features are gated by subscription plan in addition to role permissions. Six plan tiers from Free to Enterprise control which modules are available to each tenant.

Infrastructure

Hardened infrastructure

Multiple layers of protection between your data and the outside world.

Cloudflare CDN

Global CDN with DDoS protection, Web Application Firewall, and edge caching for fast, secure content delivery worldwide.

Hardened Server Stack

Nginx 1.29 with server tokens disabled, PHP 8.3 with FPM, and MariaDB with strict mode. SSH hardened with strong ciphers, limited auth tries, and secure configuration.

Security Headers

HSTS, Content Security Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy headers enforced on every response. No unsafe-eval in CSP.

API Rate Limiting

File-based rate limiting at 120 requests per minute for standard endpoints, with stricter limits for public booking (10/hr) and online orders (20/hr).

CORS Protection

Cross-origin requests are restricted to allowed origins with subdomain wildcards and tenant custom domains. Credentials are only sent for verified origins.

24-Hour Token Expiry

JWT tokens expire after 24 hours (configurable). Short-lived sessions reduce the window of exposure from stolen tokens.

Compliance

Built for compliance

The tools and practices you need to meet regulatory requirements and maintain customer trust.

PCI DSS Alignment

Payment processing is handled through PCI-certified gateways — Stripe, PayPal, Square, WiPay, and First Atlantic Commerce. Card data never touches our servers. Tokenized saved payment methods ensure cardholder data stays with the processor.

GDPR Compliance

Cookie consent banners with accept/reject. Full tenant data export via backup API for data portability. Soft-delete architecture supports right to erasure. Customers can request their data, and businesses can fulfill requests with a single click.

HIPAA Considerations

While Sales Point 360 is not itself HIPAA-certified, our architecture supports healthcare-adjacent businesses: AES-256-GCM encryption at rest, complete tenant isolation, audit logging with IP tracking, role-based access, and 2FA enforcement provide a strong foundation for compliance.

Audit Logging

Every state-changing operation is logged with user, action, entity, IP address, and tenant context. Full activity trail for accountability, forensic analysis, and regulatory compliance.

Webhook Security

All webhook deliveries are signed with HMAC-SHA256. Secrets are masked in API responses and only shown in full at creation time. Auto-disabled after 10 consecutive failures.

Training & Maintenance

Sandboxed training mode lets staff practice without affecting real data. IP-whitelisted maintenance mode allows safe updates. Training sales are excluded from reports and clearly marked on receipts.

Responsible Disclosure

Report a vulnerability

We take security seriously and welcome responsible disclosure from the community.

Contact Our Security Team

If you discover a security vulnerability, please report it responsibly. Send details to [email protected] and we will respond within 48 hours. Please include steps to reproduce the issue and any relevant technical details.

[email protected]

Secure your business today

Join thousands of businesses that trust Sales Point 360 with their operations and data.

Sales Point 360 AI
Online
Hi! I'm the Sales Point 360 assistant. I can help you with questions about our POS platform, features, pricing, and getting started. What would you like to know?