Skip to content

Security

Locked at the back-office door

Getting into the back office takes both a password and a code sent by email. Each person sees only the parts they look after, and every change is logged with who made it.

A password alone isn't enough

After the password, the system emails a 6-digit code to the staff member. The code expires in 10 minutes and allows 5 wrong attempts, and a trusted device can be remembered for 24 hours. Try signing in on the screen below, then find the code in the inbox on the right.

Everyone sees only what they need

Every staff account has one role. Menus that aren't part of the job stay hidden, and typing a link in directly won't open them either.

Can view payments, reports and account codes, but can't edit any entries.

HMenus for Accounting3/11
  • Dashboard
  • Booking Calendar(no access)
  • Class Schedules(no access)
  • Customers(no access)
  • My Clients(no access)
  • Packages(no access)
  • PaymentsView only
  • ReportsView only
  • Broadcasts · Promo Codes(no access)
  • All Logs(no access)
  • Users · Permissions(no access)

Every change carries a name and a time

Every create, edit and delete is logged automatically, along with the values that changed. If an amount or a session count doesn't add up, you can look back and see the cause right away.

Data and money take verified routes

HMAC-SHA256
Every message LINE sends to the system has its signature checked before it's processed.
0 card numbers
Members enter their card in the payment provider's window. The studio's server never receives the card number.
Once
Each payment adds sessions only once, even if the result arrives more than once.
Hourly
The database is backed up automatically, with copies kept for about 7 days.
CSRF
Every form in the system checks a token, so other websites can't send commands on a user's behalf.
Token link
The front desk check-in page opens only from a link that carries a token.