Your data is
safe with us
We take security seriously. Here's how we protect your business data.
Encryption
All data is transmitted over HTTPS with TLS encryption. Passwords are hashed using industry-standard algorithms.
Secure Sessions
Session cookies are HttpOnly, Secure, and SameSite. Session IDs are regenerated periodically to prevent fixation.
CSRF Protection
All forms are protected with CSRF tokens. Every request is validated to prevent cross-site forgery.
Rate Limiting
API endpoints and login attempts are rate-limited to prevent brute force and abuse.
Data Isolation
Multi-tenant architecture with strict tenant_id isolation. Your data is never mixed with other businesses.
Regular Backups
Your data is backed up regularly. In case of any issue, we can restore quickly with minimal downtime.
Role-Based Access
Granular role-based access control. Admin, manager, cashier, accountant, and staff roles with specific permissions.
Privacy First
Your data is never shared with third parties. We do not sell or rent your information to anyone.
Security Headers
HSTS, X-Frame-Options, X-Content-Type-Options, CSP, and other security headers are enforced.
Security Best Practices for Users
- Use a strong, unique password for your MAZDUKAN account.
- Enable two-factor authentication if available on your device.
- Never share your login credentials with anyone.
- Log out from shared or public computers after use.
- Keep your browser and operating system updated.
- Report any suspicious activity to support immediately.
Report a Vulnerability
If you discover a security vulnerability in MAZDUKAN, please report it responsibly. Do not publicly disclose the vulnerability until we have addressed it.
Email us at security@mazdukan.com with details of the vulnerability. We acknowledge all reports within 48 hours and work to resolve issues promptly.