What we can tell you, and what we cannot yet
This page is shorter than most security pages, on purpose. It lists the controls we can describe accurately today and says plainly where we are not ready to make a claim.
A short security page is a truthful one
Most security pages for software this size are written to reassure rather than to inform. They describe controls in language vague enough to survive a question — "enterprise-grade encryption", "bank-level security", "your data is safe with us" — and name standards the company has not been audited against.
We would rather hand your IT adviser a page they can actually check. So what follows is limited to controls we can state precisely. Where a control exists but we cannot yet describe its detail accurately, it is left off rather than blurred, and it will appear here when we can say something specific about it.
If you are evaluating SlickCell Pro for a business where this matters, ask us directly on a call. A short honest page and a real conversation beat a long page of adjectives.
What is in place today
Three, described in the same terms used everywhere else on this site.
- Role permissions
- Staff see and change what their role allows. Refunds, voids and price edits are gated rather than available to everyone with a login, so the actions that move money are limited to the people meant to take them.
- Audit history
- Money and stock movements are recorded with who did what, and when. A financial change adds a record rather than replacing one, so a settled invoice cannot be quietly rewritten and a reversal is itself an entry you can find later.
- Backups, by plan
- Backup frequency is part of what a plan includes: monthly on Professional, weekly on Supplier Pro and Enterprise. Starter does not include a backup schedule. This describes the cadence your plan buys, not a tested restore procedure.
Things this page deliberately does not say
Named explicitly, because the absence is the point. If a competitor's page claims these without evidence, ask them the same questions.
- No certifications
- We are not SOC 2 audited and not ISO 27001 certified, and we will not describe ourselves as "enterprise-grade" as a substitute for either. If a certification matters to your decision, we do not currently hold one.
- No encryption claim, yet
- We are not publishing an encryption statement until we can say exactly what is encrypted, where, and with what. "Encrypted" on its own tells a technical reader nothing and is trivially true of any site served over HTTPS.
- No isolation claim, yet
- Every shop's data being separate is a design requirement, not a sentence we will publish without describing how it is enforced and how that was tested. It will appear here in those terms.
- No penetration-test claim
- We have not published the results of an independent security assessment, so we do not reference one. Any page that mentions testing without naming who did it and when is telling you nothing.
This list will get shorter. Each item moves into the section above when we can describe it precisely — not when we find a comfortable way to phrase it.
Bring your technical questions to a call
If security is a deciding factor, the useful conversation is a specific one — about your data, your staff and what you need to satisfy.
