Security
Security
Locked at the back-office door
Getting into the back office takes both a password and a code sent by email. Each person sees only the parts they look after, and every change is logged with who made it.
A password alone isn't enough
After the password, the system emails a 6-digit code to the staff member. The code expires in 10 minutes and allows 5 wrong attempts, and a trusted device can be remembered for 24 hours. Try signing in on the screen below, then find the code in the inbox on the right.
Everyone sees only what they need
Every staff account has one role. Menus that aren't part of the job stay hidden, and typing a link in directly won't open them either.
Can view payments, reports and account codes, but can't edit any entries.
- Dashboard
- Booking Calendar(no access)
- Class Schedules(no access)
- Customers(no access)
- My Clients(no access)
- Packages(no access)
- PaymentsView only
- ReportsView only
- Broadcasts · Promo Codes(no access)
- All Logs(no access)
- Users · Permissions(no access)
Every change carries a name and a time
Every create, edit and delete is logged automatically, along with the values that changed. If an amount or a session count doesn't add up, you can look back and see the cause right away.
Data and money take verified routes
- HMAC-SHA256
- Every message LINE sends to the system has its signature checked before it's processed.
- 0 card numbers
- Members enter their card in the payment provider's window. The studio's server never receives the card number.
- Once
- Each payment adds sessions only once, even if the result arrives more than once.
- Hourly
- The database is backed up automatically, with copies kept for about 7 days.
- CSRF
- Every form in the system checks a token, so other websites can't send commands on a user's behalf.
- Token link
- The front desk check-in page opens only from a link that carries a token.