Each brand kept apart
Every record in Oflo belongs to one organization. Rules inside the database itself check, on every read and every change, that a person only reaches the data of the organization they belong to. Even a mistake in the app screens cannot show one brand’s data to another.
Roles and permissions
- Administrators choose who joins and give each person a role.
- Each role opens only the spaces and pages it needs, with read or write access per page. A store vendor sees the till, not the payroll.
- Sensitive actions, such as money, stock changes and payroll, are checked again by the database, not only by the screens.
- A person can belong to several organizations and switch between them, with different rights in each.
Encryption
All traffic between your devices and Oflo is encrypted with HTTPS (TLS). Data is encrypted at rest by our hosting provider. Passwords are never stored in readable form. In the mobile app, your session is kept in the phone’s secure storage.
Files and documents
Sensitive documents, such as bank statements and employee documents, live in private storage. They open through links that expire after a few minutes, so a forwarded link stops working.
Backups
The database is backed up automatically by our hosting provider. Backups are encrypted and kept for a limited time, then rotated.
Monitoring and history
- Errors are reported to our team automatically, so we often fix issues before you notice them.
- Important actions keep a history of who did what and when: stock movements, transfers, returns, payments and approvals.
- Messages from your website and courier can be protected with secret keys, set in Settings.
Connected services
Keys for WooCommerce, Aramex, email and other services are stored per organization and used from our servers, never exposed in public web pages. You can disconnect a service or replace its keys at any time from Settings.
Our team
Only a small number of Oflo team members can access production systems, and only when needed to run or support the service. They are bound by confidentiality.
What you can do
- Use a strong, unique password for each person.
- Give each role only the pages it needs.
- Remove people from your team as soon as they leave.
- Keep the keys of your connected services private.
Report a problem
If you think you found a security issue, please write to security@oflo.studio with the details. Do not access or change other people’s data while testing. We will confirm receipt within 2 working days, keep you informed, and credit your help if you wish.
In the unlikely event of a breach affecting your data, we will inform you without undue delay, tell you what happened and what we are doing about it, and help you meet your own obligations.