Security

How we protect your business data on orderYaa ERP.

Your sales, inventory, and financial data are core to your business — we treat protecting them as a core part of the product, not an afterthought.

Data in transit

All traffic between the app, our APIs, and our servers is encrypted using HTTPS/TLS. Nothing is sent to our backend over an unencrypted connection.

Account access

  • Every user signs in with their own login — no shared admin passwords
  • Role-based permissions control what each user can see and do
  • Cashier PINs and session controls protect POS terminals in-store

Data separation

Each business's data — companies, branches, and business units — is logically separated so one customer's data is never visible to another.

Infrastructure

Our backend runs on managed cloud infrastructure with regular backups, so your sales and accounting records are recoverable in the event of a failure.

Reporting a security issue

If you believe you've found a security vulnerability in orderYaa, please report it to us directly rather than disclosing it publicly, so we can investigate and fix it before it affects customers.

When you report an issue, please include:

  • Steps to reproduce the issue
  • The affected module or endpoint
  • What you were able to access or do that you shouldn't have been able to

We acknowledge every report within 2 business days and will follow up with you directly as we investigate.