PANTHEON™ Help

 Toc
 PANTHEON Help - Welcome
[Collapse]PANTHEON
 [Collapse]Guides for PANTHEON
  [Expand]Guide for PANTHEON
  [Expand]Guide for PANTHEON Retail
  [Expand]Guide for PANTHEON Vet
  [Expand]Guide for PANTHEON Farming
 [Collapse]User Manuals for PANTHEON
  [Collapse]User Manual for PANTHEON
   [Collapse]Getting Started
     First steps with PANTHEON
    [Expand]PANTHEON Installation
    [Expand]PANTHEON Basics
    [Expand]PANTHEON System data
    [Collapse]PANTHEON Security
      About PANTHEON Security
     [Expand]DATALAB Cloud Security
      PANTHEON Web Security
      PANTHEON On-Premises Security
     [Collapse]PANTHEON Mobile Apps Security
       Mobile POS Security
       VET Mobile App Security
     [Expand]PANTHEON eBusiness Security
      OLAP Security in PANTHEON 
      PAWS  (PANTHEON Web Services) Security
    [Expand]Using PANTHEON at Tecta, a fictional company
    [Expand]Frequently asked questions about Pantheon (F.A.Q.)
   [Expand]User Manual for eBusiness
   [Expand]Settings
   [Expand]Orders
    Creating new invoice
   [Expand]Goods
   [Expand]Manufacturing
   [Expand]Service
   [Expand]Help
   [Expand]Personnel
   [Expand]Financials
   [Expand]Analytics
  [Expand]User Manual for PANTHEON Retail
  [Expand]User manual for PANTHEON Vet
  [Expand]User Manual for PANTHEON Farming
[Collapse]PANTHEON Web
 [Collapse]Guides for PANTHEON Web
  [Expand]Guide for PANTHEON Web Light
  [Expand]Guide for PANTHEON Web Terminal
  [Expand]Guide for PANTHEON Web Legal
 [Collapse]User Manuals for PANTHEON Web
  [Expand]Getting started PANTHEON Web
  [Expand]User Manual for PANTHEON Web Light
  [Expand]User Manual for PANTHEON Web Terminal
  [Expand]User Manual for PANTHEON Web Legal
[Collapse]PANTHEON Granules
 [Collapse]Guides for PANTHEON Granules
  [Expand]Personnel Granule
  [Expand]Travel Orders Granule
  [Expand]Documents and Tasks Granule
  [Expand]Dashboard Granule
  [Expand]B2B Orders Granule
  [Expand]Field Service Granule
  [Expand]Fixed Assets Inventory Granule
  [Expand]Warehouse Inventory Granule
 [Collapse]User Manuals for PANTHEON Granules
  [Expand]Getting started
  [Expand]Personnel Granule
  [Expand]Travel Orders Granule
  [Expand]Documents and Tasks Granule
  [Expand]B2B Orders Granule
  [Expand]Dashboard Granule
  [Expand]Field Service Granule
  [Expand]Fixed Assets Inventory Granule
  [Expand]Warehouse Inventory Granule
[Expand]User Site

Load Time: 812.5186 ms
"
  1000007165 | 227525 | 492803 | Published
Label

Mobile POS Security

Mobile POS allows simple cash operations on Android tablets and smartphones for service providers and retailers.

Below is an overview of the key security elements that protect your data and access to the system.


Table of contents

  1. Infrastructure and Environment
  2. Network and Connectivity
  3. Access and Authentication
  4. Data Management
  5. Updates and Maintenance
  6. Regulatory Compliance
  7. Audit and Access Logging
  8. Business Continuity and Disaster Recovery

1. Infrastructure and Environment

  • The server hosting the Mobile POS database is located at a cloud service provider (e.g., Telekom), offering high levels of physical and virtual infrastructure protection.

  • Each client has a dedicated and isolated database, ensuring data separation and enhanced security.

  • The infrastructure provides reliability, redundancy, and protection against physical damage or unauthorized access.

2. Network and Connectivity

  • The connection between the mobile device and the cloud server is always encrypted, preventing interception or data snooping during transmission.

  • Data write access to the server is managed via an SQL user account with restricted rights, limited only to the respective client’s database.

  • Synchronization only transfers data that has changed since the last sync, optimizing network usage and reducing exposure.

3. Access and Authentication

  • Each user has a unique username and password.

  • The mobile app supports automatic logout after issuing a receipt, allowing shared device use while preventing unauthorized access (e.g., issuing invoices under a colleague’s account).

  • Authorization is divided into distinct permission levels:

    • Administrators have full access to all operations.

    • Cashier-level users have limited rights within the POS interface (e.g., issuing invoices, entering customers); they do not have browser-based access.

    • Cloud administrators have full rights via the web application.

    • Cloud users have read-only access via the browser interface.

  • User permissions are strictly role-based, reducing the risk of misuse or unauthorized actions.

4. Data Management

  • Data from the mobile app database is automatically synchronized with the cloud database upon key events.

  • Sync is performed regularly and only for unsynchronized or updated records.

  • The app provides two backup methods: via Wi-Fi and mobile data.

  • In addition to synchronization, cloud backups occur based on a defined schedule (hourly to monthly), ensuring data is preserved even if the device fails or is lost.

  • Periodic backup can be disabled by the user, though this is not recommended due to data security risks.

5. Updates and Maintenance

  • The system and mobile application are regularly updated to eliminate vulnerabilities and maintain optimal performance.

  • Updates include improvements in connection security, permission management, and data protection.

6. Regulatory Compliance

  • All data access and management comply with applicable data protection laws and information security regulations.

  • Separate databases for each client contribute to compliance with confidentiality and data handling requirements.

7. Audit and Access Logging

  • The system logs key events such as logins, user permission changes, synchronizations, and backups.

  • These logs ensure transparency and traceability of all user activities, supporting security audits and potential abuse investigations.

  • Access to logs is restricted to authorized support personnel only.

8. Business Continuity and Data Recovery

  • Due to the vulnerability of mobile devices, backups are performed independently of synchronization to allow quick recovery in the event of device failure or loss.

  • Backup scheduling is customizable per client, supporting uninterrupted operations and data retention.

  • The mobile app supports full offline functionality for most features, ensuring reliability and traceability even without an active internet connection.

  • For features that require internet access, users are notified with a pop-up message and must confirm before proceeding.

 

Rate this topic
Was this topic usefull?
Comments
Comment will also bo visible in forum!