Security
Your sales data, treated like money
Plain answers to the questions your IT person — or your accountant — will ask before trusting a POS with the numbers your business runs on.
Encryption everywhere
All traffic between your devices and our cloud is encrypted with TLS, and data is encrypted at rest with AES-256. Nobody reads your numbers in transit — including us.
Your own isolated database
Every business runs in its own tenant-specific database — not a shared table with a filter. Your catalog, sales and customer data are physically separated from every other merchant’s.
Access control on the till
Role-based permissions decide who can discount, refund, or void; staff sign in with device-bound PINs; and sensitive actions land in an immutable audit trail with who-did-what detail.
POPIA by design
We process personal information under South Africa’s POPIA: you can access, correct or delete the personal data we hold, and our privacy policy spells out exactly what we collect and why.
Offline data stays safe
Sales captured during an outage live on your device until they sync — they are never dependent on a third-party queue, and reconciliation into the cloud is deterministic and auditable.
No data hostage-taking
Cancel at any time and your data remains exportable. We compete on the product, not on how hard it is to leave.
Where we are honest about being early
We are an early-stage company — we do not hold SOC 2 or ISO 27001 certification yet, and we will not pretend otherwise. What we will do is walk you through our current security posture in as much detail as you need, engineer to engineer.
Questions, concerns, or a responsible disclosure? Email info@abosto.com and it will reach the people who wrote the code.
For how we handle personal information, see the Privacy Policy (including your POPIA rights).
Want the deeper walkthrough?
Bring your IT person — we'll answer the hard questions on a call.