Security & trust

It processes your data. It never owns it — only de-identified aggregates leave, with consent.

That single line is the rule everything else is built around — including that any aggregate reaches a third party only through a platform control that is closed by default. Here's how it shows up in the product.

How that shows up in the product

Read-only agent

It reads; it never writes back to your POS.

PII hashed at the source

Customer names are hashed on your network — never stored in cleartext.

Encrypted in transit

TLS from the agent to the gateway, with optional mTLS client certificates.

Access by location

Short-lived tokens and role-based access, scoped per branch.

Per-business isolation

One business can never reach another's data — enforced in the app layer.

Audit log

Every account, business, and agent change is logged with who, when, and what.

Nothing gets lost

Offline queue + replay, and a dead-letter queue for anything that fails.

Human-in-the-loop

AI mappings are advisory; an admin approves. Two admins for financials.

The Data Network

Separately from that isolation guarantee, DataHelm can compute aggregate market figures across participating businesses — de-identified, not anonymous, opt-in and off by default, never published below 5 distinct businesses, with no raw data and no personal data. Any owner can opt their business in or out at any time, and any aggregate reaches a third party only through a platform control that is closed by default.

How we treat your data

Accuracy over convenience

Financial figures are stored with full precision — never silently rounded, converted, or modified.

No false precision

If data is incomplete — like a partial day — the dashboard says so, rather than implying certainty it doesn't have.

Your data is portable

Export any entity to CSV or JSON at any time. If you downgrade or cancel, your data stays readable and exportable during a grace window.

No dark patterns

Clear limits communicated before you hit them, pricing up front, and cancellation in one click.

Want the technical detail?

We're happy to walk your security team through the architecture, data handling, and access model.

Talk to the team