Your shop's data, hosted in London and locked to your shop
Customer records, unlock codes, stock and takings are the most sensitive things a repair shop holds. Here is exactly how SlickCell protects them, on every plan, from the day you sign up.
In London, encrypted, and separate from every other shop
- Hosted in London, on every plan
- Your shop's database runs in a London data centre. That is the same on Starter as on Enterprise: UK data residency is not an upgrade you have to ask for.
- Encrypted in transit and at rest
- Every connection to SlickCell is encrypted with TLS, and the database is encrypted at rest with AES-256. That covers the app, the till, the phone scanner and the customer tracking page.
- Every shop sealed off from every other
- Row-level security is switched on for every table in the database. Each query is checked against the shop you belong to by the database itself, so another shop's records cannot be reached from the app, from the API or by a changed link. The rule is covered by automated database tests.
Staff see what their job needs, and nothing more
- Roles enforced by the database
- Owner, manager, technician, sales and accountant each see and change only what the role allows. The rule lives in the database, not just in hidden buttons, so a permission cannot be sidestepped from outside the screen.
- Money-moving actions limited
- Voids and write-offs are limited to owners and managers. Editing a sold unit or handing a device over unpaid asks for a reason, and the reason is kept with the record.
- Two-factor sign-in
- Every account can add an authenticator app, so a stolen password alone does not open the shop. Switching it off needs both the password and a current code.
- Customer unlock codes kept apart
- Device passcodes are stored separately from the customer record and are revealed only to the roles that work on the device. Every reveal is logged with who looked and when.
- Automatic sign-out
- A till left open signs itself out after the period of inactivity you choose, with a warning first.
A record of every change, and your data always yours
- Append-only audit trail
- Changes to repairs, stock, customers, invoices and payments are written to an audit trail with who made them and when. Entries are added, never edited, and only owners and managers can read them.
- Paid invoices cannot be rewritten
- Once an invoice is settled it is locked. A refund or correction is a new entry that points at the original, so the history your accountant reads is the history that happened.
- Deleted records can be restored
- Deleting a record moves it to the bin first, where it can be brought back. Nothing important disappears because of one wrong click.
- Export whenever you like
- Repairs, stock, payments, profit and loss, tax and payroll reports export to CSV at any time, from the screen you are already on. Your records are yours to take to your accountant, or anywhere else.
No card numbers held, and eyes on the system around the clock
- We never store a card number
- Your subscription is paid on the secure pages of a PCI DSS Level 1 payment provider. At the till, card takings are recorded by amount and method on the sale, so no customer card data ever passes through SlickCell.
- Monitored around the clock
- Errors in the app and on the server are reported to us the moment they happen, with customer personal data stripped out before the report is sent.
What shop owners ask us
In London. Your shop's database runs in a London data centre on every plan, including Starter. UK data residency is standard, not an enterprise add-on, and the data is encrypted in transit (TLS) and at rest (AES-256).
Your shop's database is hosted in London on every plan. The full list of the service providers that process data for SlickCell, with what each one does and where, comes with our data processing agreement, which any customer can ask for at hello@slickcell.com. Customers are given 30 days' notice before a provider is added or changed.
No. Row-level security is enabled on every table, so the database itself checks every request against the shop you belong to. Another shop's records cannot be reached from the app, from the API, or by editing a link, and automated database tests cover that rule.
Only the roles that work on the device. Passcodes are stored apart from the customer record, an accountant login never sees them, and every reveal is logged with the name of the person and the time.
No. Your subscription is paid on a PCI DSS Level 1 payment provider's own pages, and card sales at the till are recorded by amount and method only. Keep the card machine you already have: SlickCell takes no cut of your card takings.
Yes. Any account can add an authenticator app, so a password on its own is not enough to sign in, and turning it off needs the password and a current code.
Yes, at any time. Repairs, stock, payments and every report export to CSV from the screen they are on, so your accountant gets the same figures the app shows, and moving your records never depends on asking us.
Put your own shop on it for fourteen days
Same security on the trial as on every paid plan. No card, and nobody has to ring you back first.
