Security, privacy & trust
How PosBiz protects your data, your customers and your compliance posture.
Isolation
Tenants resolve only from a verified host registry. Each tenant uses a separate database (or a strictly prefixed scope on restricted hosts), tenant-scoped file storage and signed subscription snapshots. Cross-tenant access attempts are denied and logged.
Application security
Argon2id password hashing, HttpOnly SameSite cookies with rotation, CSRF tokens on every state change, rate limiting, prepared statements everywhere, least-privilege granular permissions, audited support impersonation with a visible banner.
Payments
Card data never touches PosBiz. Ziina payment intents are created and verified server-side; entitlements activate only after verified payment; webhooks are deduplicated and reconciled.
Data handling
Product images are stripped of EXIF and geo metadata. Camera barcode scanning decodes on-device and never uploads frames. IMEI and device histories are protected operational data with masked display and audited reveal/export.
Compliance posture
PosBiz is not an accredited e-invoicing provider; structured submissions travel through your appointed accredited ASP via our connector. Country packs activate only with official rules — draft packs cannot run live transactions.
Operations
Encrypted automated backups with restore drills, idempotent provisioning with rollback, queue dead-letter review, structured logs with correlation IDs and truthful status screens during any delay.