Security as an engineering property
I approach security as part of how a system is built: who is allowed, how that is checked, what is recorded and what happens when one layer is wrong. I do not hold penetration-testing or other security certifications, and this page does not imply that I do.

Authentication and sessions
Passwords in Rechvix use Argon2id; KinetiRx uses bcrypt. TOTP multi-factor authentication is available in Rechvix, OrderRestro and the construction ERP, and in Rechvix it can be made mandatory for owners, admins and accountants. The construction ERP adds backup codes, a device session list and remote revocation, so a lost laptop can be signed out from elsewhere.
OrderRestro uses an httpOnly session cookie with a PIN quick-switch for shared tills, a compromise between security and how restaurants actually work.
Authorisation
Every protected route in KinetiRx is authorised on the server against the employee's role and permissions. The interface hiding a button is not access control. OrderRestro's permissions are granular and individually toggleable. Rechvix scopes permissions to branch and warehouse.
API authentication
Submify accepts submissions with an API key header and optionally verifies an HMAC signature, while its dashboard uses JWT access and refresh tokens. Keys can be rotated per account and per project.
Tenant separation and row-level security
Rechvix enforces tenant isolation twice: PostgreSQL row-level security and an organisation filter in every repository query. It also separates the schema-owning role from the runtime role, because a table owner bypasses row-level security. The full reasoning is in Row-level security is not your only tenant boundary.
Audit logging
The construction ERP keeps an append-only log of logins, permission changes and security events. Rechvix writes audit entries in the same transaction as the change.
Secrets, dependencies and least privilege
Secrets stay out of repositories and are supplied at deploy time. Submify and Rechvix run govulncheck, and Submify runs npm audit, before releases. Findings I cannot fix immediately are recorded in the changelog and not hidden. Databases are never published to the host, and runtime database roles hold no schema privileges.
Infrastructure hardening
TLS at the edge, firewalls that deny by default, minimal published ports and segmented networks are covered on the networking and infrastructure pages.