Security

Your data is
safe with us

We take security seriously. Here's how we protect your business data.

Encryption

All data is transmitted over HTTPS with TLS encryption. Passwords are hashed using industry-standard algorithms.

Secure Sessions

Session cookies are HttpOnly, Secure, and SameSite. Session IDs are regenerated periodically to prevent fixation.

CSRF Protection

All forms are protected with CSRF tokens. Every request is validated to prevent cross-site forgery.

Rate Limiting

API endpoints and login attempts are rate-limited to prevent brute force and abuse.

Data Isolation

Multi-tenant architecture with strict tenant_id isolation. Your data is never mixed with other businesses.

Regular Backups

Your data is backed up regularly. In case of any issue, we can restore quickly with minimal downtime.

Role-Based Access

Granular role-based access control. Admin, manager, cashier, accountant, and staff roles with specific permissions.

Privacy First

Your data is never shared with third parties. We do not sell or rent your information to anyone.

Security Headers

HSTS, X-Frame-Options, X-Content-Type-Options, CSP, and other security headers are enforced.

Security Best Practices for Users

  • Use a strong, unique password for your MAZDUKAN account.
  • Enable two-factor authentication if available on your device.
  • Never share your login credentials with anyone.
  • Log out from shared or public computers after use.
  • Keep your browser and operating system updated.
  • Report any suspicious activity to support immediately.

Report a Vulnerability

If you discover a security vulnerability in MAZDUKAN, please report it responsibly. Do not publicly disclose the vulnerability until we have addressed it.

Email us at security@mazdukan.com with details of the vulnerability. We acknowledge all reports within 48 hours and work to resolve issues promptly.