Security

Built to see receipts, not card numbers.

safetill sits between two systems you already trust. Here is exactly what it stores, how it protects it, and what it never touches.

What we process

From your POS: payment and refund events at receipt level — amount, currency, line items, tender type, till (device) and location identifiers, and timestamps. From Verkada: the list of cameras in your organization and the Helix event types you create.

What we never process

Credentials

Verkada API keys and POS OAuth tokens are encrypted with AES-256-GCM before they are stored. The encryption key is kept in a managed secret store and is only available to the running service. Verkada short-lived tokens are cached in memory and reissued automatically.

Tenant isolation

Every workspace is a separate tenant in a safe and secure database, with isolation enforced by the database itself rather than by application code. One workspace can never read or write another workspace's data.

Webhooks and APIs

Infrastructure

safetill runs on Google Cloud and is hosted in the United States for now. Authentication is provided by Clerk; billing by Stripe. We hold no payment card data of our own customers either.

Your controls

Reporting a vulnerability

Please email the support address shown in the app with details and we will acknowledge within two business days.

Stop guessing what happened behind the counter.

Start a connection

Four quick steps · no hardware · no card data