Trust & Security

Security, in writing.

This page is the record of how PandazPOS protects a store: the standards its systems meet, how money moves, and where the walls are. No badges we did not earn the right to print, and no claims we cannot back on paper.

Every merchant we bring on is underwritten before day one, and we answer for them after. If any line here matters to your decision, write us and a person replies.

Same counter, different ledger.

Security is the floor, and everyone stands on it. Hold the rest of the page up to the big names and watch where the ink runs out.

PandazPOSThe big-name POS
The floorAny register worth plugging in clears this bar. So do we.
F-01PCI DSS Level 1 payment rails
F-02EMV certified counter hardware
F-03Encrypted in transit and at rest
F-04SOC 2 audited cloud
Where the ledger splits
L-01Vape and tobacco welcomeUnderwritten day oneIf approved. Until flagged.
L-02Counter hardware costOn us$700 and up
L-03Who picks up when you callOur own crew, not outsourcedTier 1, please hold
L-04Age verification at checkoutBuilt inThird-party add-on
L-05Your brand on the registerWhite-label, standardnot offered
L-06Full reporting and owner appIncludedHigher tier
L-07Loyalty across locationsIncludedAdd-on fee
Their column reads from published pricing pages and merchant agreements for mainstream POS platforms, mid 2026; specifics vary by provider and plan. Our column is in writing above, and attestation documents are yours on request: [email protected]
Section 01 · Your money

How your money moves.

We run the counter; certified payment rails run the cards. What reaches our systems is a reference token, never the number.

1.1
The terminal encrypts a card the instant it is read.
Encryption happens inside PCI PTS certified hardware at the counter, before anything leaves the device.
1.2
Payments settle on PCI DSS Level 1 infrastructure.
Level 1 is the standard's highest tier, the same tier the largest platforms in the world settle on.
1.3
Card numbers never touch our servers.
We keep an encrypted reference for refunds and reporting. If our systems were opened tomorrow, there would be no card numbers to find.
1.4
We onboard every merchant ourselves.
Every account is screened and underwritten at signup: identity, anti-money-laundering, and sanctions checks. We bring you on, and we answer for the account after.
1.5
Your PCI scope stays small.
Because the register never handles raw card data, the compliance burden on your store shrinks with it.
Section 02 · Your data

Where the walls are.

One store can never see another store's data. The database enforces it, not just the app.

2.1
Row-Level Security on every store's data.
Isolation is written into the database itself. A query from one store cannot return another store's rows, no matter what the application asks for.
2.2
Isolation is tested before anything ships.
An automated test attempts to cross store boundaries on every release. If it gets through, the release does not.
2.3
Encrypted at rest and in transit.
AES-256 on stored data and backups. TLS 1.2 or better on every connection, terminal to app to database.
2.4
Backed up automatically.
Database backups run on schedule and are encrypted like everything else.
2.5
White-label per location.
Your brand, your environment, your data.
Section 03 · Infrastructure

Built to stay up.

The platform runs on audited, certified infrastructure, filtered at the network edge.

3.1
SOC 2 Type II audited cloud.
The infrastructure carrying store data is independently audited every year against security, availability, and confidentiality controls.
3.2
ISO 27001 certified data centers.
Physical and operational security certified to the international standard.
3.3
DDoS protection and a web application firewall at the edge.
Traffic is inspected and filtered before it ever reaches the application.
3.4
Offline-ready at the counter.
A WiFi drop does not stop the line. Keep ringing; the register syncs when the connection returns.
Section 04 · Age & product

Regulated retail, handled.

Built for age-gated products by people who sell them.

4.1
ID scanning and age verification at checkout.
Age-gated categories prompt verification before the sale completes.
4.2
Timestamped verification records.
A defensible record for your files, rolling out to all stores now.
4.3
CCPA and CPRA rights honored.
Export or delete your data on request, minus what the law requires us to keep.
4.4
We do not sell your data. Not yours, not your customers'.
Financial records are handled to bank-grade, GLBA-aligned privacy standards.

"I keep your sales data walled off the same way I'd want mine. If you can't trust the register, you can't run the shop."

Adam · shop owner · builder of PandazPOS

Found something? Tell us.

Good-faith reports get a reply from a person, not a queue.

Send details and steps to reproduce; we acknowledge within two business days. Please don't access data that isn't yours or run disruptive tests against live stores.

Email security