Posflect is the system of record for your sales, inventory, staff, and customers — so we built it on the assumption that trust has to be earned with real engineering decisions, not just promises. Here's exactly how we protect your data, keep the platform available, and handle security issues when they come up.
Every business gets its own database, not just its own rows
Posflect doesn't put every company's data in one shared database and separate it with a tenant-ID column — a design where a single bug in a database query could leak one company's data into another's results. Instead, every business that signs up gets its own dedicated database, provisioned automatically the moment the account is created. There's no shared table any tenant's staff could accidentally, or intentionally, query into a different company's records — the isolation is structural, not just a filter in application code.
Encrypted where it matters
The credentials used to connect to your company's own database are encrypted at rest, never stored or logged as plain text. Every connection to Posflect — from a browser, a cashier's device, or our own backend — travels over HTTPS, with a TLS certificate issued and automatically renewed for your business's own subdomain.
Backed up automatically, restorable on demand
Posflect backs up every business's database on an automatic schedule (weekly by default, adjustable from your own Settings screen), and keeps a rolling history of recent backups so a mistake made days ago doesn't mean losing everything since. You can also trigger a manual backup at any time from the Backups screen, and an admin can restore a previous backup themselves, without waiting on us.
Built to keep selling, even offline
A dropped internet connection shouldn't mean a cashier can't ring up a sale. Posflect actively checks real connectivity — not just whether your device thinks it's online — and if the connection drops, queues checkout transactions locally on the device, syncing them automatically the moment the connection returns, so a short outage doesn't stop the register.
Access control, down to the individual staff member
Every staff account is protected by its own login, and every session uses an expiring, signed authentication token — an inactive or logged-out session can't be replayed later. Business owners control exactly which staff can see which screens and perform which actions from a dedicated Roles & Permissions setup, rather than every employee getting the same access as the owner.
Reporting a security issue
If you believe you've found a security vulnerability in Posflect, please email us at security@posflect.com — we take reports seriously and respond as quickly as we can.
Questions
For anything else about how we protect your data, see our Privacy Policy, or contact us at hello@posflect.com.