Tenant isolation
Application access is scoped by tenant, branch, role, and permission-aware API paths.
Security
BranchOrbit uses tenant-scoped access patterns, encrypted integration tokens, role-aware admin surfaces, and secure deployment practices. No public page can guarantee absolute security, but the platform is designed with practical controls.
Application access is scoped by tenant, branch, role, and permission-aware API paths.
POS access and refresh tokens are encrypted server-side and are never sent to the frontend.
BranchOrbit does not claim to store full card numbers; card processing is handled by payment processors such as Stripe.