Security and data protection
Last updated: 11 October 2026
A separate database for your company
Every company gets its own database for each service it subscribes to — Accounting, Warehouse, CRM and HR — instead of one table shared by all customers. Your company's data is never mixed with another company's, and it is not shared between your different services.
Sign-in and permissions
- The site and the systems are served over HTTPS, so data is encrypted in transit.
- Passwords are stored hashed (bcrypt); nobody, including our team, can read them.
- Repeated failed sign-in attempts are temporarily blocked.
- Role-based permissions: each user sees and changes only what their role allows.
Audit trails and sensitive data
- Accounting and HR keep an audit trail of who changed what, and when.
- In HR, national ID, passport and insurance numbers are stored encrypted and are never written to the audit log.
- Employee documents are kept in private (non-public) storage, and every download is logged.
Payments
We do not store card details. Bank and wallet transfers happen outside the site, and online card payment — where offered — is processed entirely by the payment provider, Kashier.
Your data is yours
We use your company data only to run the service, and we never sell it. You can ask for a copy or for deletion when you leave. Details are in the Privacy Policy.
Reporting a security issue
If you notice a vulnerability or suspicious behaviour, email info@cutme.org.