# Security

How Tulz protects your data – and what you can do yourself.

### What Tulz does

- **Separate businesses**: every business only sees its own data. The separation is done by the database itself, not just by the program.
- **Encrypted connection**: Tulz only runs over HTTPS; the browser remembers that the site may only be opened encrypted.
- **Passwords** are never stored in plain text, only as a hash – the same goes for the keys for "Stay signed in", password links, kiosk devices and the interface.
- **Encrypted credentials**: credentials for other services (email sending, shops and payment providers, single sign-on, translation, webhooks) are stored encrypted in the database. Whoever only steals the database cannot do anything with them.
- **Content policy**: the browser only runs the program parts of Tulz. If someone manages to smuggle foreign code into a text field, that code does not run.
- **Protection against guessing**: account lock after 5 wrong passwords, plus a limit per internet connection. Neither the sign-in nor "Forgot password" reveals whether a user name exists.
- **Sessions**: sign-out after inactivity (*Settings → Sign-in*), a new password ends all other sessions, security notice by email for a new password, new email address or new passkey.
- **Support only with your approval**: support only sees your business if an administrator allows it under *Help & support → Support access* – limited in time, revocable at any time, every access in the log. Users, settings, kiosk devices, webhooks, customer area and passkeys remain locked.
- **No connections into the internal network**: addresses you enter (webhooks, label printers, single sign-on) are only contacted by the server if they are publicly reachable on the internet.
- **Uploaded files** are checked by their content, renamed and only delivered after sign-in. They can never run as a program.
- **Daily check**: a security check verifies, among other things, whether program files have been changed or foreign files appear, and reports anything suspicious to the operator immediately.

### What you can do

- **Set up passkeys** (*My profile → Passkeys*) – the best protection against stolen or guessed passwords, especially for administrators.
- **Own accounts**: every employee gets their own account with the right role; administrator only for those who really need it. Deactivate accounts of employees who have left.
- **"Stay signed in"** only on your own phone or computer – for the shared tablet in the workshop there is the kiosk.
- **Revoke support access** once the issue is solved; "read only" is usually enough.
- **Received a security notice you did not trigger?** Change your password immediately and remove unknown passkeys and devices in your profile – or ask the administrator to remove the account's passkeys and devices.

---

Source: https://tulz.work/en/help/article/security · As of 2026-10-08 · Tulz
