Four boundaries you can check.
01 · Your organization
Another merchant cannot cross your record boundary.
- Record rule
- Every merchant record is scoped to its organization. A location narrows work; it never replaces that organization boundary.
- Role ceiling
- org_admin is the merchant’s own ceiling. Platform operators sit outside the merchant’s roles; they are not another shop role.
02 · Your devices
Trust belongs to a named register—and can be revoked.
Almacén Rivera · Centro
Caja 2
María García · Manager
Revoked
This browser can start no new sales. Its queued operations remain inspectable and exportable for recovery.
What the browser holds
- A bounded local operation queue after device setup.
- A request for persistent browser storage, with trust state visible.
- Inspectable, exportable recovery data—not an unlimited offline promise.
03 · Your people
Fixed roles. Literal limits. A reason on every sensitive movement.
- org_adminOrganization-wide merchant administration; no platform-operator role.
- managerOperates assigned locations; cannot cross the organization boundary.
- cashierRuns counter sales; no merchant administration.
The record does not rewrite history.
Refunds, voids, adjustments and shift closes are append-only audited movements. Each requires a reason, so a sensitive change has an actor and an explanation.
- Refund + reason
- Void + reason
- Adjustment + reason
- Shift close + reason
04 · Payment data
No PAN. No CVV. Ever.
- Tillo never displays or stores card numbers.
- A manual external-card tender is a reference, not proof of provider payment.
- An integrated terminal becomes paid only after a confirmed provider result—never a client timeout.
Receipts in v1 are explicitly non-fiscal. Security boundaries apply to every plan; no card provider is bundled.
Start with Caja