GWiZ™ Software Solutions

Security

How client systems are protected. Stated as what is actually configured, not as a list of intentions.

Last updated: 20 September 2026

Security

Encryption

AES-256 at rest across every store, managed by Google Cloud. TLS enforced in transit, with HTTP redirected to HTTPS at the edge. Both apply regardless of region.

Access to your systems

Sign-in is through Microsoft 365 / Entra ID or Google Workspace against your own tenant, so there is no additional password for us to issue or for you to revoke separately. Where passkeys are enabled, staff confirm who they are with Touch ID, Face ID, Windows Hello or a security key.

Our hub applications are invite-only. There is no self-service registration: an account exists because an administrator created it, or because an identity provider vouched for the address. Requests to the registration endpoint are refused rather than queued.

Credentials

Secrets are held in Google Secret Manager and injected at runtime. They are not in source control, not in container images, and not in browser-visible code. Where a service must act as another identity it does so through short-lived tokens issued by Google rather than a downloadable key — our organisation policy forbids creating service-account keys, and our integrations are built to satisfy that rather than to seek an exception to it.

How changes reach production

Every change runs the full test suite before it is built. A new revision is deployed holding no traffic, is checked on its own URL, and receives traffic only after it answers. The previous revision stays in place and traffic can be returned to it in one command.

On-premise connections

Where cloud software reaches equipment on your floor, the connection is outbound from your network. There is no inbound port to open, no static address to publish, and nothing for a scanner to find.

QuickBooks Online

Our ERP application connects under a single scope and holds its authorisation tokens server-side, never in a browser. What it reads, what it writes, how long derived records are kept, and how to disconnect are set out in the Privacy Policy.

Accessibility

Interfaces are built and tested to WCAG 2.2 Level AA. Conformance is documented per engagement rather than claimed in general. The standards that govern, and how they relate to one another, are set out in our Terms.

Reporting a vulnerability

Email info@gwizweb.com with enough detail to reproduce the issue. We acknowledge within two business days and will tell you what we found and when it was fixed. We will not pursue legal action against anyone who reports a genuine issue in good faith and does not access, modify or retain other people’s data while doing so.

Where this is expanded

Data residency store by store, tenant isolation and backup retention are in our Governance & Architecture statement. What we collect and how long we keep it is in the Privacy Policy.