Skip to content
Security

Your shop's data, hosted in London and locked to your shop

Customer records, unlock codes, stock and takings are the most sensitive things a repair shop holds. Here is exactly how SlickCell protects them, on every plan, from the day you sign up.

Where your data lives

In London, encrypted, and separate from every other shop

Hosted in London, on every plan
Your shop's database runs in a London data centre. That is the same on Starter as on Enterprise: UK data residency is not an upgrade you have to ask for.
Encrypted in transit and at rest
Every connection to SlickCell is encrypted with TLS, and the database is encrypted at rest with AES-256. That covers the app, the till, the phone scanner and the customer tracking page.
Every shop sealed off from every other
Row-level security is switched on for every table in the database. Each query is checked against the shop you belong to by the database itself, so another shop's records cannot be reached from the app, from the API or by a changed link. The rule is covered by automated database tests.
Who can see what

Staff see what their job needs, and nothing more

Roles enforced by the database
Owner, manager, technician, sales and accountant each see and change only what the role allows. The rule lives in the database, not just in hidden buttons, so a permission cannot be sidestepped from outside the screen.
Money-moving actions limited
Voids and write-offs are limited to owners and managers. Editing a sold unit or handing a device over unpaid asks for a reason, and the reason is kept with the record.
Two-factor sign-in
Every account can add an authenticator app, so a stolen password alone does not open the shop. Switching it off needs both the password and a current code.
Customer unlock codes kept apart
Device passcodes are stored separately from the customer record and are revealed only to the roles that work on the device. Every reveal is logged with who looked and when.
Automatic sign-out
A till left open signs itself out after the period of inactivity you choose, with a warning first.
Nothing changes quietly

A record of every change, and your data always yours

Append-only audit trail
Changes to repairs, stock, customers, invoices and payments are written to an audit trail with who made them and when. Entries are added, never edited, and only owners and managers can read them.
Paid invoices cannot be rewritten
Once an invoice is settled it is locked. A refund or correction is a new entry that points at the original, so the history your accountant reads is the history that happened.
Deleted records can be restored
Deleting a record moves it to the bin first, where it can be brought back. Nothing important disappears because of one wrong click.
Export whenever you like
Repairs, stock, payments, profit and loss, tax and payroll reports export to CSV at any time, from the screen you are already on. Your records are yours to take to your accountant, or anywhere else.
Payments and monitoring

No card numbers held, and eyes on the system around the clock

We never store a card number
Your subscription is paid on the secure pages of a PCI DSS Level 1 payment provider. At the till, card takings are recorded by amount and method on the sale, so no customer card data ever passes through SlickCell.
Monitored around the clock
Errors in the app and on the server are reported to us the moment they happen, with customer personal data stripped out before the report is sent.
Security questions

What shop owners ask us

In London. Your shop's database runs in a London data centre on every plan, including Starter. UK data residency is standard, not an enterprise add-on, and the data is encrypted in transit (TLS) and at rest (AES-256).

Your shop's database is hosted in London on every plan. The full list of the service providers that process data for SlickCell, with what each one does and where, comes with our data processing agreement, which any customer can ask for at hello@slickcell.com. Customers are given 30 days' notice before a provider is added or changed.

No. Row-level security is enabled on every table, so the database itself checks every request against the shop you belong to. Another shop's records cannot be reached from the app, from the API, or by editing a link, and automated database tests cover that rule.

Only the roles that work on the device. Passcodes are stored apart from the customer record, an accountant login never sees them, and every reveal is logged with the name of the person and the time.

No. Your subscription is paid on a PCI DSS Level 1 payment provider's own pages, and card sales at the till are recorded by amount and method only. Keep the card machine you already have: SlickCell takes no cut of your card takings.

Yes. Any account can add an authenticator app, so a password on its own is not enough to sign in, and turning it off needs the password and a current code.

Yes, at any time. Repairs, stock, payments and every report export to CSV from the screen they are on, so your accountant gets the same figures the app shows, and moving your records never depends on asking us.

Put your own shop on it for fourteen days

Same security on the trial as on every paid plan. No card, and nobody has to ring you back first.