Skip to content
Penahak now runs hotels, restaurants and retail on one ledger.
Penahak
Security & data

Security, privacy and who owns your data

Your accounting system holds your customer list, your margins, your payroll and your tax position. This page describes the controls that protect it, in enough detail to be checked — and is explicit about the questions we answer in writing rather than on a web page.

Every control below can be demonstrated in a live system during your evaluation.

Ownership

Your records are yours

This is the first thing to settle with any cloud vendor, because everything else depends on it.

You own the data you enter

Your ledgers, customers, suppliers, stock, employees and documents belong to your business. We hold them to run the service for you, and for no other purpose.

You can get it out at any time

Export to Excel, CSV and PDF is built into every report rather than being a paid extra or a support request. You are never holding your own history hostage to a subscription.

We do not trade on it

The business records inside a customer’s workspace are not used for advertising, not resold, and not used to build products for anyone else.

Your workspace is separate

Each organisation’s data is held in its own workspace, separate from every other customer’s. Users authenticate into your organisation and see only its records.

You can see what was done to it

User activity logging records actions taken in your workspace, and the accounting audit trail records every posting and every correction with the user and reason attached.

You can leave with it

If your subscription ends there is an agreed wind-down period in which you export your records. The terms of that are set out in the service agreement, not decided at the time.

Read the full privacy policy

Access

Who can get in, and what they can reach

Most real-world losses are not sophisticated attacks. They are an ex-employee whose login still worked, or a member of staff who could reach something they should never have been able to reach.

Getting in

  • Two-factor authentication, so a stolen password is not enough on its own
  • Restriction by IP address, with a per-user exception where someone genuinely needs to work from elsewhere
  • Account start and expiry dates, so seasonal and temporary staff lose access automatically rather than when someone remembers
  • Accounts can be suspended immediately without deleting the person’s history

What they can do once in

  • Granular role-based permissions, assigned by job rather than by person
  • Navigation follows the role, so people are not shown work they cannot perform
  • Approval requirements on discounts, price overrides, voids and corrections
  • Access scoped to a branch, so a branch manager sees their branch and not the group
  • User activity logging across modules

Least privilege is worth the setup time. The most common configuration mistake we see is one powerful role shared by everyone, because it was quicker on day one. We will push back on that during implementation — segregation of duties is the control auditors test first.

Integrity

Why the numbers cannot be quietly changed

Security is usually discussed as keeping people out. For an accounting system the harder problem is making sure that what is inside cannot be altered without trace.

From an operational action to a reportA four-step chain: an operational action creates one source document carrying a safe-retry reference, which posts to the ledger with tax and dimensions, which a report reads and can drill back through to the original document. 1 Operational action
A sale, a folio charge, a pay run
2 Source document
Created once, with a safe-retry reference
3 Ledger posting
Tax, settlement and dimensions attached
4 Report
Drills back to the source document ID
Retrying any step returns the same document reference — never a duplicate.

Posted documents are immutable

A posted invoice, receipt, payment, stock voucher or ledger entry cannot be edited in place. There is no administrative route around this, and that is the point.

Corrections leave a trail

A mistake is fixed with a credit note, debit note or reversing journal that references the original document, and records the approving user and the stated reason.

A retry cannot duplicate a posting

Checkout, night audit, online payments and stock issues each carry a safe-retry reference, so repeating a failed action returns the document that already exists instead of creating a second one.

Configuration is gated

Stage-based setup checks block posting until ledgers, tax terms, numbering and mappings are correct, so misconfiguration is caught before it produces a period of wrong entries.

Every total is traceable

Any figure in any report drills back through to the documents that produced it, which is what makes an audit a review rather than a reconstruction.

Backups are taken and restorable

Both automatic and manual backup and restore are part of the platform. Ask us to demonstrate a restore during your evaluation rather than taking the word for it.

Deliberately not on this page

The questions we answer in writing, not in marketing copy

Security pages are full of phrases like "bank-grade encryption" and "99.9% uptime" that mean nothing without the detail behind them. We would rather answer these properly, to your procurement team, in a document we can be held to.

Request the security questionnaire

  • Where data is hosted, and under whose jurisdiction
  • Encryption in transit and at rest, stated precisely
  • Backup frequency, retention periods and tested recovery objectives
  • Availability commitments and how they are measured
  • Incident response and breach notification process
  • Sub-processors and third parties with any access
  • Staff access to customer data, and how it is controlled and logged
  • Independent testing or certification, and its scope
  • Data deletion on exit, and what we are legally required to retain

A note on how to read any vendor’s security page. If a claim has no scope, no date and no way to verify it, it is decoration. Ask for the questionnaire, ask who signed it, and ask when it was last reviewed — of us and of everyone else you are considering.

Bring your security review to us

If your organisation has a vendor assessment process, send it. We would rather work through your questionnaire than have you infer answers from a web page.

Procurement and IT questions are answered by the team responsible, not by sales.