VendoPOS
Data & Security

Data & Security Architecture

Enterprise-grade protection running through every register transaction.

NeonDB managed PostgresRA 10173 aligned
Infrastructure controls

Protection built into the architecture, not bolted on.

Database Scoping

Fenced tenants, completely isolated.

Fenced tenant parameters isolate every record completely inside our NeonDB instance. Each query is bound to a single tenant key — there is no path for one merchant’s data to surface in another’s.

  • Row-level tenant key on every record
  • Zero cross-tenant joins, by design
  • Managed, encrypted Postgres on NeonDB
  • Isolation enforced at the data layer
Session Layer Protection

Sessions that never leak.

Secure, HTTP-only cookie sessions propagate straight to our backend — never exposed to client-readable storage and never replayable off-device.

Audit Resiliency

Every invoice, accountable.

Immutable sequence-integrity tracking covers all retail invoices — gapless numbering, tamper-evident records, and a replayable audit trail.

Encryption in Transit

TLS on every hop between register, browser, and backend — no plaintext crosses the wire.

Least-Privilege Access

Scoped roles and a narrow, fully audited support path. Staff see only what their role allows.

Continuous Backups

Routine snapshots with point-in-time recovery, so a bad day never becomes lost data.

Aligned with the Data Privacy Act.

Our controls map to RA 10173 and the issuances of the National Privacy Commission. Have a security or compliance question? Talk to the team that runs the platform.

Contact our team
Security
security@vendopos.app
Headquarters
Cebu City, Philippines
Phone
0915 515 2314