Security is the foundation
Fine-grained roles and permissions, revocable user and device tokens, signed reader events, encryption at rest and strict tenant isolation.
9 capabilities, per screen
View, create, edit, delete, manage, finance, audit, devices and alerts — finance fields stay protected by default.
Short-lived, always revocable
Rotating refresh tokens let you revoke a user session or a device instantly.
Replay-proof, rate-capped
HMAC signatures with a timestamp window and nonce, plus rate and size caps, keep reader ingest trustworthy.
Keys live outside your tenant DB
Device secrets are AES-256 encrypted, tenants are strictly isolated, data is encrypted in transit, and everything is audit-trailed.
Your data, export anytime
Export your data whenever you want. SSO/SAML, data residency and 2FA are on the roadmap.
How it works
Assign roles
Grant least privilege
Revoke anytime
Everything included
- RBAC (9 capabilities)
- Per-screen guards
- Revocable user/device tokens
- Signed ingest
- Encryption at rest / in transit
- Tenant isolation
- Audit trail
- Data export
- SSO / data residency / 2FA (roadmap)
Frequently asked questions
Ready to account for every asset?
Tag, track and audit everything you own — from a handheld scanner to a boardroom report.
No card required · Live in a day · TZS/USD/GBP