Company separation
Tenant-scoped access
Users and operating records are linked to a company. Backend authorization checks company and branch scope before protected data is returned or changed.
Security at AfiaLedger
AfiaLedger combines access controls, tenant separation, server-trusted records, and auditable actions. This page describes controls currently implemented in the pilot—not future promises or compliance certifications.
Company separation
Users and operating records are linked to a company. Backend authorization checks company and branch scope before protected data is returned or changed.
Authentication
Passwords and staff PINs are stored as secure hashes. Access and rotating refresh sessions can be revoked, and repeated incorrect staff PIN attempts trigger a temporary lock.
Staff devices
The owner authorizes phones used for staff PIN access. Trusted devices can be identified, renamed, and revoked; revocation also invalidates staff sessions issued to that phone.
Operational records
Protected transaction timestamps are generated by the server in UTC instead of trusting editable time metadata submitted by a phone.
Network resilience
Relevant offline submissions use idempotency keys so retries caused by unstable connectivity do not silently create duplicate operational records.
Traceability
Important actions are recorded with the responsible user and server timestamp, giving authorized owners a history for review and investigation.
Production web and API traffic is delivered over HTTPS. Users should install the Android app only through AfiaLedger’s official download page.
Company owners remain responsible for accurate user assignments, strong owner passwords, prompt device revocation, and removing access when staff roles change.
Current pilot position
AfiaLedger does not currently claim ISO 27001, SOC 2, PCI DSS, or any other independent security certification. Security controls will continue to be reviewed as the pilot expands.