How Tulz protects your data – and what you can do yourself.
What Tulz does
- Separate businesses: every business only sees its own data. The separation is done by the database itself, not just by the program.
- Encrypted connection: Tulz only runs over HTTPS; the browser remembers that the site may only be opened encrypted.
- Passwords are never stored in plain text, only as a hash – the same goes for the keys for "Stay signed in", password links, kiosk devices and the interface.
- Encrypted credentials: credentials for other services (email sending, shops and payment providers, single sign-on, translation, webhooks) are stored encrypted in the database. Whoever only steals the database cannot do anything with them.
- Content policy: the browser only runs the program parts of Tulz. If someone manages to smuggle foreign code into a text field, that code does not run.
- Protection against guessing: account lock after 5 wrong passwords, plus a limit per internet connection. Neither the sign-in nor "Forgot password" reveals whether a user name exists.
- Sessions: sign-out after inactivity (Settings → Sign-in), a new password ends all other sessions, security notice by email for a new password, new email address or new passkey.
- Support only with your approval: support only sees your business if an administrator allows it under Help & support → Support access – limited in time, revocable at any time, every access in the log. Users, settings, kiosk devices, webhooks, customer area and passkeys remain locked.
- No connections into the internal network: addresses you enter (webhooks, label printers, single sign-on) are only contacted by the server if they are publicly reachable on the internet.
- Uploaded files are checked by their content, renamed and only delivered after sign-in. They can never run as a program.
- Daily check: a security check verifies, among other things, whether program files have been changed or foreign files appear, and reports anything suspicious to the operator immediately.
What you can do
- Set up passkeys (My profile → Passkeys) – the best protection against stolen or guessed passwords, especially for administrators.
- Own accounts: every employee gets their own account with the right role; administrator only for those who really need it. Deactivate accounts of employees who have left.
- "Stay signed in" only on your own phone or computer – for the shared tablet in the workshop there is the kiosk.
- Revoke support access once the issue is solved; "read only" is usually enough.
- Received a security notice you did not trigger? Change your password immediately and remove unknown passkeys and devices in your profile – or ask the administrator to remove the account's passkeys and devices.