Demo tillSales today ₦1,284,650.00Receipts printed 187Queued offline 0Duplicates after sync 0
Home/Security
Every change has a name on it

Most retail fraud is internal. So is most of our security.

Firewalls are not what protects a shop. The threat is far more often a trusted person making a small change nobody can see. Nostra is built so that every change is signed and nothing financial can be erased.

Access

Nobody gets more than their job needs.

Access is granted by named capability, not by rank. Refunding, selling an expired batch, adjusting stock, opening the drawer, seeing cost prices and exporting the ledger are all separate permissions.

  • 199 permissions, each granted or withheld individually
  • Branch scope enforced where data is fetched, not where it is shown
  • PIN sign-in at the till, with throttling and lockout
  • Mail and integration secrets encrypted and never shown back
ROLE · CASHIEREDITABLE
sales.createring up salesGRANTED
sales.refundrefund a saleWITHHELD
sales.override_expirysell an expired batchWITHHELD
inventory.adjustchange stockWITHHELD
reports.cost_pricessee marginsWITHHELD

Audit trail

A record nobody can quietly edit.

The audit log is not a feature you switch on. It is written by the same code that performs the action, in the same database transaction, so an action cannot succeed while its record fails.

  • User, branch, till and device on every sensitive action
  • Before and after values, so an edit shows what changed
  • Overrides and authorisations name who gave them
  • Financial records voided, never deleted, with the void itself logged
  • Exportable for an accountant or inspector, behind its own permission
AUDIT · PRICE CHANGEA-88412
WhoA. Bello, branch managerPIN
WhereSurulere, till 0114:02:11
BeforeRice, 5kg9,200.00
AfterRice, 5kg9,500.00
Editable laterby anyoneNO

Backups and restore

A backup you have never restored is a rumour.

Most businesses discover their backup does not work on the worst day of the year. Nostra treats restore as the feature and backup as the prerequisite, which is why restore is something you can rehearse.

01

Scheduled and verified

Backups run on a schedule and are checked after they are written. A backup that cannot be read is reported as a failure, not recorded as a success.

AUTOMATIC
verified after write
02

Off-site, in storage you control

Copies go to S3-compatible storage under your own credentials and your own bucket. If you ever stop using Nostra, your backups are still somewhere you own.

YOUR BUCKET
your credentials
03

Downloadable as one archive

Any backup can be pulled down as a single compressed file straight from the browser. No support ticket, no waiting.

ONE FILE
direct download
04

Restore that keeps its own paperwork

A restore preserves the backup and restore records themselves, so the history of what was restored and when survives the restore.

SELF-PRESERVING
the trail survives
05

Rehearsed, not assumed

A disaster recovery check runs on demand. Better to find a problem on a Tuesday afternoon than during an actual emergency.

ON DEMAND
run it any time

Hosting

Hosted by us, or entirely by you.

Some groups want their data physically under their control. That is a legitimate position rather than one we argue with.

Hosted

We run, patch and back it up. You get a URL and staff accounts.

Self-hosted

Installs on ordinary shared hosting or your own server.

In transit and at rest

Served over HTTPS. Passwords hashed. Secrets encrypted with a key held outside the database.

Updates

Every release is tested against the full suite before it reaches a till.

This page describes how the product behaves, which you can check for yourself on a walkthrough. It claims no certifications, because Nostra does not hold any yet. When it does, the audit report will be linked here.

Your data

If you leave, you leave with everything.

Export products, customers, sales, stock movements and the full audit trail in CSV, XLSX or PDF whenever you like. No request form, no fee, no waiting period.