Skip to main content
Security

What we do — and don't do — with your store's data.

Jewelers handle high-value merchandise and long customer histories. You should not need to guess what happens under the hood. This page is meant to answer everything without you having to email us — but if we've missed your question, we're one message away.

At a glance
Legal entity
Fourfold LLC (Sacramento, CA)
Hosting
Firebase / Google Cloud (US)
Auth
Firebase Authentication + 2FA
Data in transit
TLS 1.2+ (HSTS enforced)
Data at rest
AES-256 (managed by Google Cloud)
Backups
Automated daily · retained 30 days
Accounts

Who can sign in — and how we know it's them

Two-factor authentication on every account

TOTP-based 2FA is available for every staff account and required for store owners by default. No SMS-based fallback (SMS is the attack surface, not the defense).

Role-based access

Owner, manager, and counter-staff roles ship out of the box. Roles are per store — a manager at Location A does not see Location B's data unless explicitly granted.

Session management

Sessions expire after inactivity. Owners can revoke any staff session from the admin dashboard.

Your data

Yours, always — with no lock-in

One-click CSV export

Your full catalog, customer records, sales history, repair queue, and layaway ledger export to CSV any time. No ticket, no wait.

AI does not train on your data

Prompts sent to the AI Design Generator and inputs to the Growth Agents stay in your store. We do not use them to train models and we do not share them across stores.

Data location

All customer data is stored in Firebase / Google Cloud US-region datacenters. If you need EU or India residency, tell us and we'll walk through options.

Network + infrastructure

The plumbing

Encrypted in transit

TLS 1.2+ on every connection. HSTS enforced. HTTP requests get 301'd to HTTPS at the edge.

Encrypted at rest

AES-256, managed by Google Cloud key management. Backups are encrypted the same way.

Payments never touch our servers

Card processing is handled by Stripe. Card numbers, CVVs, and expiry dates go directly from your customer's device to Stripe — we only see the last four digits and a token.

Operations

How we run the service

Least-privilege access

Engineers do not have production customer-data access as part of their default role. Access requires an explicit request with a documented reason.

Automated daily backups

Retained for 30 days. Point-in-time restore available for the last 24 hours.

Vulnerability disclosure

Found something? Email security@fourfoldllc.com. We respond within one business day and credit responsible reporters if desired.

On the roadmap

What we're honest about NOT having yet

SOC 2 Type II

We're not certified today. If your procurement team needs it and you're a serious multi-store lead, tell us and we'll share our current runbook + timeline.

EU / India data residency

US-only today. Available on request for multi-store deployments.

SSO / SAML

Not shipped yet. On the roadmap for chain accounts. Firebase supports it under the hood.

Missing something you'd need for procurement?

If your IT / security team has a checklist, send it. We'll answer every row — or tell you honestly if we're not there yet and where we are on our roadmap.

Send us your checklist →