Security
Last updated · 20 July 2026
Architecture
Every pharmacy is a fully isolated tenant. Row-level security is enforced in the database — not just the application layer — so a bug in one path can't leak another workspace's data.
Encryption
TLS 1.3 in transit, AES-256 at rest, encrypted backups with keys rotated on schedule.
Access control
Role-based access, mandatory 2FA for admin roles, and immutable audit logs for every privileged action.
Reporting a vulnerability
Please email security@pharmapos.org. We acknowledge within 24 hours and never take legal action against good-faith researchers.