Security, privacy & trust

How PosBiz protects your data, your customers and your compliance posture.

Isolation

Tenants resolve only from a verified host registry. Each tenant uses a separate database (or a strictly prefixed scope on restricted hosts), tenant-scoped file storage and signed subscription snapshots. Cross-tenant access attempts are denied and logged.

Application security

Argon2id password hashing, HttpOnly SameSite cookies with rotation, CSRF tokens on every state change, rate limiting, prepared statements everywhere, least-privilege granular permissions, audited support impersonation with a visible banner.

Payments

Card data never touches PosBiz. Ziina payment intents are created and verified server-side; entitlements activate only after verified payment; webhooks are deduplicated and reconciled.

Data handling

Product images are stripped of EXIF and geo metadata. Camera barcode scanning decodes on-device and never uploads frames. IMEI and device histories are protected operational data with masked display and audited reveal/export.

Compliance posture

PosBiz is not an accredited e-invoicing provider; structured submissions travel through your appointed accredited ASP via our connector. Country packs activate only with official rules — draft packs cannot run live transactions.

Operations

Encrypted automated backups with restore drills, idempotent provisioning with rollback, queue dead-letter review, structured logs with correlation IDs and truthful status screens during any delay.