Skip to content
Zaxore
Trust

Security and your data

What the Zaxore app does to protect your business’s data — written from the app’s own code, without certifications or promises we cannot show.

App code last reviewed: 2026-09-30

This page describes how the app works. It does not describe how the service is hosted or operated (server location, server backups, uptime or email delivery); ask support if you need those answered.

Built in for every business

Part of the app itself. There is nothing to switch on.

Your data stays with your business

  • Every request is tied, on the server, to the business you are signed in to, and only that business’s records come back.
  • Zaxore support staff can open a business only in a support mode that is read-only by default, needs a stated reason, ends on its own and is recorded; the business sees it in its Security Center.

People see only what their role allows

  • Permissions are checked by the server on every request, not only hidden in the app.
  • Cost, margin and profit figures are removed on the server for anyone without the cost permission — including the default Cashier role.

Signing in

  • Passwords and staff PINs are stored only as salted hashes, never in readable form.
  • Repeated wrong passwords or PINs are slowed down and lock the account for a while.
  • Each user can see their signed-in devices and sign any of them out.

A record of what happened

  • Sign-ins, failed attempts, approvals and permission changes go into an audit log that the app never edits or deletes. Owners can review it in the app.

Sensitive items are kept encrypted

  • Backups, integration credentials and webhook secrets are stored encrypted by the app, and private files are shared only through short-lived links.

Payments

  • Zaxore does not process or store card numbers. Card payments are recorded at the register; card terminals are not connected yet.

Online ordering links

  • Each branch’s ordering link uses a random token you can regenerate at any time, and the server re-checks every price and stock level before accepting an order.

Controls you turn on or set

Available to every business. They protect you once you use them, so check them when you set up.

Two-step verification

  • Every user can turn on two-step verification with an authenticator app, with one-time recovery codes. It is off until each user turns it on; we recommend it for owners and managers.

Where each person can work

  • You can limit staff to specific branches and pin a cashier to one register; the server then refuses requests outside that scope.
  • Staff invitations work once, expire (48 hours by default) and fix the role, branch and register you chose.

Approvals at the register

  • Manual discounts need a reason. Discounts above your limit (10% by default) and cash-drawer differences above your threshold (10 by default) need a manager to approve from their own signed-in device. You set these limits.

Your data, when you need it

  • Admins can download spreadsheet (CSV) exports of products, customers, suppliers, sales, inventory and stock movements, and an encrypted backup that can be restored into Zaxore.
  • You can export or anonymize a customer’s data when they ask, and marketing messages go only to customers who opted in.

Closing an account

  • Owners can schedule deletion of their business account in the app. There are 14 days to cancel; after that the account is closed and staff logins are anonymized, while sales and accounting records are kept.

What this page does not claim

Zaxore does not currently claim any security certification or compliance attestation (such as SOC 2, ISO 27001 or PCI DSS). This page also does not state a hosting region or a server-side backup schedule. If you need any of these answered for your business, write to support.