Permissions first
Every record carries a tenant and a role. Staff can only see what their role allows. Owner, manager, counter, scanner, and field roles are first-class.
This statement describes the security controls currently used across NoxOrigin’s hosted products and assisted deployments. It does not make compliance claims beyond the controls described here.
Effective: Last reviewed: 2 August 2026
Every record carries a tenant and a role. Staff can only see what their role allows. Owner, manager, counter, scanner, and field roles are first-class.
Discounts, approvals, edits, and authentication events are recorded. Logs are exportable and kept read-only for owners.
Email and password authentication uses password hashing, rate-limited login attempts, session management, and controlled password-reset flows. Additional authentication methods remain product-specific and are documented as they become generally available.
Production services run on managed hosting and database infrastructure. Traffic is encrypted in transit over HTTPS. Tenant identifiers and role checks are applied at the application boundary, and backups and recovery procedures are reviewed as part of operational maintenance.
Sensitive actions are logged where the product supports audit history. Access is limited to the team members and service accounts needed to operate the products. Customers may request export or deletion according to the applicable product terms and retention requirements.
Infrastructure, email, messaging, and analytics providers are used only where required for the selected product or measurement settings. We investigate suspected incidents, communicate material impact where required, and review corrective actions. Contact us for the current subprocessors relevant to your deployment.
Report a vulnerability to [email protected]. We acknowledge new reports within 2 business days and triage within 5 business days.