Security

Security is a core feature of KounterPOS. We handle financial and business data, and we take that responsibility seriously. This page describes the measures we take to protect your data.

Security Measures

๐Ÿ”’

Encryption in Transit

All data transmitted between your browser and our servers is encrypted using TLS 1.2+ (HTTPS). Internal service communication (gRPC between Rust ledger, Go gateway, and Python AI) is also encrypted in transit.

๐Ÿ’พ

Encryption at Rest

All data is stored in PostgreSQL with encrypted storage volumes provided by our infrastructure partner. Database backups are also encrypted at rest.

๐Ÿข

Tenant Isolation

Every query is scoped to your organization using Postgres Row-Level Security (RLS) policies. Tenant A can never read, modify, or even enumerate Tenant B's data โ€” enforced at the database layer, not just the application.

๐Ÿ”‘

Password Security

Passwords are hashed using Argon2id (memory-hard, GPU-resistant) with unique per-user salts. We never store or have access to your plaintext password.

๐ŸŽซ

Authentication & Sessions

JWT-based session tokens with short expiry (15 minutes). Refresh tokens are rotated on use. Sessions can be revoked instantly via the logout endpoint which denylists the token in Redis.

๐Ÿ“ฆ

Automated Backups

Automated daily backups of all databases with encrypted storage. Backup restoration is tested on a regular schedule to ensure recoverability. See our Deployment runbook for details.

โšก

Rate Limiting

All public endpoints are rate-limited to prevent abuse. Authentication endpoints are limited to 10 requests per minute per IP. Additional rate limiting is applied to API endpoints based on plan tier.

๐Ÿ”

Dependency Auditing

Continuous dependency vulnerability scanning in CI/CD: cargo audit (Rust), govulncheck (Go), pip-audit (Python), and npm audit (frontend). Critical vulnerabilities block deployment.

Compliance & Standards

DPDP Act 2023 Compliance

In Progress

India's Digital Personal Data Protection Act compliance including consent management, data subject rights, and grievance officer appointment.

OWASP ASVS Self-Audit

Completed

Application security verified against OWASP Application Security Verification Standard Level 2.

Incident Response

In the event of a data breach, we follow a documented incident response runbook:

  • Immediate containment and impact assessment
  • Notification to the Data Protection Board of India (DPBI) without delay
  • Formal breach report to DPBI within 72 hours of becoming aware of the breach
  • Affected users notified promptly with clear information about what happened and what to do
  • Post-incident review and remediation within 30 days

Report a Vulnerability

If you discover a security vulnerability in KounterPOS, please report it responsibly by emailing security@kounterpos.digital. We will acknowledge your report within 24 hours and work with you to understand and resolve the issue. We do not pursue legal action against good-faith security researchers.