Fill in legal details in src/config/brand.ts (BRAND.legal): LEGAL_NAME, LEGAL_ADDRESS, GOVERNING_STATE, GOVERNING_COUNTY.
DRAFT FOR LEGAL REVIEW. Not legal advice.
Security overview
Effective date: October 11, 2026 · Last updated: October 11, 2026
This is a short, honest summary of how we protect your data today. We list only practices we actually follow. We do not hold SOC 2, ISO 27001 or any other security certification, and we do not claim to.
Encryption in transit #
All connections to the website and the app use HTTPS (TLS).
Each company's data is kept separate #
Every record belongs to one company. Database access rules check which company a user belongs to on every request, so one company cannot see another company's data.
Access controls #
Roles decide what each person in your company can see and do. Only our staff who need access to support you can reach customer data, and only for that purpose.
Audit logs #
Important actions in the app, such as approvals, changes to pay and settlements, and user changes, are written to an activity log.
Backups #
Backups of the database are handled by our hosting provider.
Payments #
Card details are entered on Stripe's hosted form and never touch our servers. Masar OS records money and does not move it, so we never hold your funds or bank credentials.
Reporting a security issue #
Email info@masar10x.io with the subject "Security". Please do not test against other customers' data.
Masar OS keeps records of invoices, pay and settlements. It does not move money. Questions: info@masar10x.io