Security built on zero trust

SaleStreams protects every transaction, admission and customer record with envelope encryption, hardware-backed key storage, and continuously rotated certificates — end to end.

Our security pillars

Every layer of the platform — from checkout terminals to the API gateway — is designed around a zero-trust posture: nothing is processed unless it can be independently verified and decrypted.

Zero-Trust Architecture

No payload is trusted or processed unless it decrypts successfully with current key material. Every request is independently verified rather than assumed safe.

End-to-End Encryption

Application data is encrypted at the message level, not just in transit — outbound requests are sealed with the gateway's public certificate and only the intended recipient can decrypt them.

Hardware-Backed Key Storage

Private keys are held in a local secure enclave and never leave it. On Android hardware, keys are generated and used inside the device Keystore — hardware-backed via StrongBox where available, or the Trusted Execution Environment otherwise.

Short-Lived Certificates

Certificates are refreshed daily with a 24-hour lifetime, limiting the exposure window of any single credential and ensuring compromised material expires quickly.

Encrypted Network Tunnel

Connections to backend services run inside a dedicated encrypted tunnel, adding a network-layer barrier in addition to message-level encryption — two independent layers of protection.

Resilient Key Recovery

Local key stores are backed up on a regular schedule. If anomalous activity is detected, the local store is purged and reinstated from the most recent trusted backup.

How our platform protects your data

A simplified view of the startup and request flow that secures every SaleStreams device before it can transact.

Secure connection established

On startup, each device opens an encrypted tunnel to our backend infrastructure before any application traffic flows.

Identity verified

The device authenticates using credentials held in its local secure key store — never stored in plain application state.

Fresh certificates issued

On successful authentication, the device requests a new short-lived certificate from our internal certificate authority.

Keys stored securely

Issued certificates and key material are written directly to the secure local store — never exported, never logged.

Every message independently verified

Each request and response is encrypted and decrypted using this key material — data that fails to decrypt is rejected outright, regardless of source.

Compliance & certifications

SaleStreams is built to meet the regulatory and industry standards visitor attractions and their customers expect, backed by a resilient, multi-region hosting footprint.

UK GDPR + EU GDPR US CCPA/CPRA PCI DSS Level 1 SOC 2 Type II ready ISO 27001 99.99% Uptime SLA
UK
Core region
EU
Data centre
US
Data centre
APAC
Data centre

Responsible disclosure

We take the security of our platform seriously and welcome reports from the security research community. If you believe you've discovered a vulnerability in SaleStreams, please contact us at sales@salestreams.net with details so our team can investigate promptly.

For questions about our security architecture, compliance certifications, or a customer security review, please reach out via our contact page.

Have a security question?

Our team can walk you through our architecture, certifications and data handling practices in detail.

Talk to Our Team View Privacy Policy