TajirPoint
Data Security

Enterprise-grade security
for every merchant.

From a single kiryana to a 50-branch chain — every merchant gets the same AES-256 encryption, zero-trust access controls, and 99.9% uptime SLA.

Encryption

Data at restAES-256, key rotation every 90 days
Data in transitTLS 1.3 (1.2 minimum, older disabled)
Database backupsEncrypted before leaving primary region
Key managementAWS KMS with hardware-backed HSM

Access control

Internal accessZero-trust, MFA required for all staff
Production accessBreak-glass with full audit log, reviewed monthly
API authenticationOAuth 2.0, short-lived tokens (1-hour TTL)
Merchant rolesGranular RBAC — cashier, manager, owner, API

Infrastructure

Cloud providerAWS — practices aligned with ISO 27001 & SOC 2
Uptime SLA99.9% monthly (cloud sync). POS works offline.
BackupsDaily, geo-redundant, 30-day retention
DDoS protectionAWS Shield Standard + CloudFront WAF

Testing & audits

Penetration testingRegular internal security reviews
Dependency scanningAutomated daily via Snyk + Dependabot
SAST / DASTIntegrated in CI/CD — every pull request
Bug bountyResponsible disclosure via security@tajirpoint.com

Standards & compliance

ISO 27001 practices
Aligned to the standard
SOC 2 practices
Aligned to the standard
AWS infrastructure
Hosted on AWS
ZATCA e-invoicing
Saudi e-invoicing support
FBR integration
Pakistan POS-IRN support

Incident response

We have a documented incident response plan. If something goes wrong, you'll know — fast. Every security incident is triaged, contained, and disclosed transparently.

Live status page →
1
Detect & contain0–1 hr

Automated alerts triage and isolate affected systems.

2
Assess & notify1–4 hr

Severity assessed. Affected merchants notified via email and in-app.

3
Remediate4–24 hr

Root cause fixed, patch deployed, access reviewed.

4
Report & improvePost-incident

Full post-mortem published on status.tajirpoint.com.

Found a vulnerability?

We welcome responsible disclosure. Email security@tajirpoint.com with a description and reproduction steps. We'll acknowledge within 24 hours, keep you informed, and never pursue legal action against good-faith researchers.