ScanSewa handles your orders, payments and customer data — so we treat protecting it as a first-class feature, not an afterthought. Here’s exactly how we keep your business safe.
From the network to the database, each layer is designed to fail safe and keep your tenant's data yours alone.
All traffic is served over HTTPS/TLS with HSTS (2-year, preload) enforced across every domain. No data moves over plain HTTP.
Every API request is verified with a signed JWT. Sessions live in httpOnly, SameSite cookies the browser cannot read, and Developer API keys are read-only and scoped to exactly what each integration needs.
Your data is pinned to your business by the verified token on every request — one account can never read or modify another tenant’s orders, customers or finances.
User-supplied content is sanitized before rendering, security headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) are set platform-wide, and the image/asset surface is locked to trusted hosts.
Runs on hardened, enterprise-grade cloud infrastructure with managed, encrypted databases and object storage. Rate limiting protects every endpoint, and CORS is restricted to ScanSewa-owned origins.
We collect only what the product needs to run your business, never sell your data, and give you control over it. See our Privacy Policy and Data Processing Addendum.
Found a vulnerability? We want to hear from you. Email a detailed report and we'll acknowledge it quickly, keep you updated, and credit you once it's resolved. Please give us a reasonable window to fix issues before any public disclosure.
security@scansewa.comOur practices are built around widely-recognised privacy principles (including GDPR-style data-subject rights). We're actively maturing toward formal certifications as we grow. Our data-handling commitments are documented in our legal policies.
See how ScanSewa keeps multi-location businesses secure while moving fast — book a walkthrough with our team.