Security
Encryption in transit (TLS 1.3) and at rest (AES-256). Field-level encryption for sensitive identifiers.
Multi-tenant isolation enforced at the database layer; every financial record is tenant-scoped.
The register integration is structurally outside PCI DSS scope — no cardholder data is ingested.
SOC 2 Type II is targeted within 18 months of launch. 7-year financial-record retention.
Last updated 2026.