Workspace isolation starts before data access
Staff sessions, customer portals, secure links, files, jobs and webhooks must resolve to one registered company. Missing or conflicting company context is rejected.
Your financial data should never feel like a black box. See how Kaupify separates companies, protects identities, verifies sensitive requests and gives businesses practical control over their information.
Security is strongest when the boundaries are visible. Kaupify checks identity, company context and request integrity before opening a workspace or accepting a sensitive update.
Staff sessions, customer portals, secure links, files, jobs and webhooks must resolve to one registered company. Missing or conflicting company context is rejected.
Salted PBKDF2-SHA256 password hashes, permissions, optional two-factor authentication, session expiry and login rate limits protect access.
State-changing browser actions use CSRF protection. Production cookies can be Secure, HttpOnly and SameSite, with security headers at the application edge.
Hosted payment providers handle card details. Payment updates are accepted through signed callbacks tied to the correct company and transaction.
Administrators decide which tools staff can reach. Important administrative and financial actions create an audit trail.
The application reports unavailable when required secrets, persistent storage or the tenant database boundary is not ready.
The Kaupify owner support console uses separate authorization and does not accept subscriber administrator passwords.
Every request starts without subscriber data access. Access is restored only from a consistent signed session, a secure public link or a verified integration signature.
Kaupify uses business data to deliver the workflows a customer chooses, protect accounts and maintain the service. Core accounting and POS functions do not require advertising cookies.
To operate accounts, apply permissions and protect sign-in.
Company administrators manage staff accounts, roles and access.
To confirm eligibility for the time-limited New Business price and prevent duplicate claims.
Kaupify retains only the result and necessary evidence. Registry credentials and full registry responses are not stored in subscriber accounts.
To provide the accounting and operational modules the subscriber selects.
The subscriber controls what is entered, imported, exported and retained, subject to record-keeping duties.
To exchange the information required by an integration configured by the customer.
Authorized users choose which integrations to configure or disconnect.
To diagnose failures, investigate misuse and keep the service reliable.
Retention should remain limited to operational and legal needs.
An essential session cookie keeps users signed in and protects authenticated requests. Optional analytics should be documented and controlled before activation.
Ask us about access controls, data handling, backups, incident reporting or a planned integration.