Enterprise Infrastructure & Trust

CustomerPilot Security Architecture

How we protect merchant data, cashier sessions, and customer loyalty records.

JWT & Role-Based Access Control

Cryptographically signed sessions separate merchant administrators, store staff, and platform operators with strict permission scopes.

Multi-Tenant Merchant Isolation

Every customer queue, reward transaction, and stamp card is strictly scoped by merchant ID across all database queries.

Encryption in Transit & Rest

All communication runs over TLS 1.3. Google OAuth refresh tokens and API credentials are stored encrypted at rest.

Write-Ahead Logging (WAL) Durability

High-concurrency SQLite WAL mode prevents transaction locks during simultaneous peak-hour cashier check-ins.

© 2026 CustomerPilot Inc. · Autonomous Merchant Retention SaaS