Security
Security is a core feature of KounterPOS. We handle financial and business data, and we take that responsibility seriously. This page describes the measures we take to protect your data.
Security Measures
Encryption in Transit
All data transmitted between your browser and our servers is encrypted using TLS 1.2+ (HTTPS). Internal service communication (gRPC between Rust ledger, Go gateway, and Python AI) is also encrypted in transit.
Encryption at Rest
All data is stored in PostgreSQL with encrypted storage volumes provided by our infrastructure partner. Database backups are also encrypted at rest.
Tenant Isolation
Every query is scoped to your organization using Postgres Row-Level Security (RLS) policies. Tenant A can never read, modify, or even enumerate Tenant B's data โ enforced at the database layer, not just the application.
Password Security
Passwords are hashed using Argon2id (memory-hard, GPU-resistant) with unique per-user salts. We never store or have access to your plaintext password.
Authentication & Sessions
JWT-based session tokens with short expiry (15 minutes). Refresh tokens are rotated on use. Sessions can be revoked instantly via the logout endpoint which denylists the token in Redis.
Automated Backups
Automated daily backups of all databases with encrypted storage. Backup restoration is tested on a regular schedule to ensure recoverability. See our Deployment runbook for details.
Rate Limiting
All public endpoints are rate-limited to prevent abuse. Authentication endpoints are limited to 10 requests per minute per IP. Additional rate limiting is applied to API endpoints based on plan tier.
Dependency Auditing
Continuous dependency vulnerability scanning in CI/CD: cargo audit (Rust), govulncheck (Go), pip-audit (Python), and npm audit (frontend). Critical vulnerabilities block deployment.
Compliance & Standards
DPDP Act 2023 Compliance
In ProgressIndia's Digital Personal Data Protection Act compliance including consent management, data subject rights, and grievance officer appointment.
OWASP ASVS Self-Audit
CompletedApplication security verified against OWASP Application Security Verification Standard Level 2.
Incident Response
In the event of a data breach, we follow a documented incident response runbook:
- Immediate containment and impact assessment
- Notification to the Data Protection Board of India (DPBI) without delay
- Formal breach report to DPBI within 72 hours of becoming aware of the breach
- Affected users notified promptly with clear information about what happened and what to do
- Post-incident review and remediation within 30 days
Report a Vulnerability
If you discover a security vulnerability in KounterPOS, please report it responsibly by emailing security@kounterpos.digital. We will acknowledge your report within 24 hours and work with you to understand and resolve the issue. We do not pursue legal action against good-faith security researchers.
Related pages: Privacy Notice ยท Data Rights ยท Grievance Officer