Built around store isolation and recovery.
Report a suspected vulnerability privately to security@shoplite.africa. Do not include passwords, reset links, PINs, secret keys or live customer data.
Core protections
- Every server request is authenticated and restricted to the authorised business.
- Owner, manager, cashier, inventory, accountant and read-only roles follow least privilege.
- Provider secrets remain server-side; webhook events are verified, matched and deduplicated.
- Backups use authenticated encryption and are bound to the originating tenant.
- ShopLite treats an offline sale as complete only after writing the full receipt to durable local storage and reading back the exact payload. If that verification fails, the basket remains unchanged for retry; stable identifiers and conflict detection prevent duplicate synchronisation.
Password recovery
Reset links expire after 30 minutes, work once, and a new request supersedes every earlier unused link. A successful reset revokes all existing ShopLite sessions. Open only the newest link delivered to the account email and never share it with support.
Responsible disclosure
Send reproduction steps, affected version and impact. Give us reasonable time to investigate before public disclosure. We will acknowledge valid reports, prioritise serious issues and communicate remediation status.
Merchant responsibilities
Use strong unique passwords, remove former staff promptly, protect unlocked devices, review unusual stock or payment activity and restore only trusted backups.
