MicroBeet is now on Android and iOS. Get the app

Security you can check

We are boring about security so you can be exciting about growth

This is your accounts and your money, so we treat it that way. Here is exactly what protects it, in plain words.

  • AES-256 encryption
  • Passwordless sign-in
  • Role-based access
  • Audit log
  • Isolated business data
  • Your own payment gateway

Bank details go in a vault

Bank account numbers, UPI IDs and payment gateway keys are encrypted with AES-256 before they are stored. Decryption keys are stored separately and rotated regularly.

No passwords to leak

You sign in with a one-time email code. Codes are stored only as hashes, expire in 10 minutes and stop working after 5 wrong tries. No password database to breach.

Your customers pay you, not us

Payments go through your own gateway account. Funds settle to you directly and never pass through MicroBeet. We never see card details.

Everyone sees only what you allow

Give each team member a role. Permissions are checked on every request, so nobody wanders into the wrong screen or downloads data they should not see.

A receipt for every change

Important actions are logged with who did it, what changed and when. Export the log when your auditor asks. Logs are immutable once written.

Old invoices stay old

An issued invoice keeps the client details it was issued with. Tax is calculated on the server, money uses exact decimal math, and stock changes are recorded, never overwritten.

Your data lives in its own room

Your business is isolated from every other business on the platform. Database queries are scoped to your business ID, and records are not left behind in browser storage.

Lost a phone? Lock it out

See every device that is signed in and sign any of them out remotely. The mobile apps add an optional PIN lock for extra protection.

Hard to hammer

Rate limits, cross-site request checks, secure cookies, validated inputs and checked file uploads help block attacks. Security headers are set on every response.

Report a security vulnerability

If you discover a security issue, please report it to security@microbeet.com. We take all reports seriously and will respond within 48 hours.

Please include:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact
  • Your contact information

We appreciate responsible disclosure and will credit researchers who report valid issues (unless you prefer to remain anonymous).

Your auditor or IT lead has questions? Good. We like those.