Security that supports controlled operations.
Checkout Core is designed with operational access and separation in mind. This page explains implemented product controls without making unsupported certification or compliance claims.
Data separation
The application uses tenant-aware data separation so operational data is scoped to the appropriate customer context.
Access controls
Role-based permissions and branch-specific access help teams give people the access they need for their responsibilities, rather than broad access by default.
Traceability
Audit logging records relevant operational and access activity to support review and accountability.
Secure transport and authentication
The production service is delivered over HTTPS and uses authenticated sessions. Product and infrastructure controls continue to be reviewed as the service evolves.
Responsible reporting
Do not send sensitive information in public channels. Use the established Checkout Core project contact channel to report a potential security issue.