You're deciding whether to trust a piece of software with your register and your merchant account. Marketing pages usually answer that with a row of logos. This page does it differently: every security claim below is paired with the artifact behind it — a test that runs, a design that makes the bad outcome impossible, or a process that actually happened.
A SOC 2 badge. We don't hold that certification, so we don't show one. We'd rather show you the architecture.
A "PCI certified" claim. Instead: card data never reaches our servers at all — which is what keeps that conversation short.
Seven specific claims, each with its artifact. Show this page to your bookkeeper or your IT friend — it's written for them too.
This is the most important fact on the page, so it comes first. When a customer pays at your counter, the card is read by the payment terminal and travels straight to the payment gateway. Batchly is never in that path — it can't leak, log, or mishandle a card number it never receives.
$23.40 and txn_id — an amount and a reference. No card number, ever.Each card states what we do, then names the thing that backs it up. If a vendor can't tell you the artifact behind a security claim, the claim is decoration.
Batchly is multi-tenant — many stores, one platform. Every row of every store's data is isolated with Postgres row-level security, enforced by the database engine. One operator can never read another's products, sales, or customers, even if application code has a bug.
An automated proof script, not a policy doc. A test signs in as one tenant and attempts to read another tenant's data across the schema; the run passes only when every attempt comes back empty. Isolation is something we execute, not something we assert.
The credentials that move your money — your payment-gateway keys — are stored in a server-side encrypted vault. They can be written in during setup, and they are used only by locked server-side code when a payment runs.
No read path to the browser. There is no endpoint that returns a stored key to any client, dashboard, or API response. A compromised laptop at your shop — or ours — can't exfiltrate what nothing will hand over.
An automated watchdog monitors the platform 24/7 — while you're closed, while we're asleep — watching for anomalies and misbehavior rather than waiting for a customer to report a problem.
It's automated, so it never gets bored. The watchdog is running software, not a calendar reminder — coverage doesn't depend on a human remembering to check.
Voids, refunds, price changes, overrides — the actions that matter in a store with cash and cards — are written to a tamper-evident audit trail. If a record is altered, the alteration is detectable.
Tamper-evident by construction. The trail is built so edits leave evidence — useful when you're reconciling a drawer, and essential when you're settling a dispute with an employee or a processor.
Per-user roles mean the weekend cashier can sell without being able to issue refunds, change prices, or export your customer list. Owner, manager, cashier — each is a different set of permissions.
Enforced in the product, per user. Roles are checked on the action, not just hidden in the menu — an account without the permission can't perform the operation, whatever it clicks.
Batchly has a full test mode: live data and test data are kept separate, so trying a workflow, training a new hire, or testing an integration never creates a fake sale in your real reporting or moves real money.
Separation is structural, not a label. Test transactions live apart from live ones — the same separation our own developers and API users rely on every day. See the developer docs →
Security isn't a launch-day state, it's a habit. Batchly runs recurring security audits and ships the fixes — and keeps the unglamorous fundamentals in place underneath.
If you believe you've found a security issue in Batchly, we want to hear about it from you first — and we'll take it seriously. Email us with enough detail to reproduce what you saw, and a human on our team will read it.
✉ hello@batchly.shop · subject line "Security" Please give us a reasonable window to investigate and fix before sharing details publicly. We won't pursue anyone acting in good faith to report a genuine issue.Bring your bookkeeper or your IT friend to the call — we'll walk through any claim on this page in as much depth as you want, and give you a straight answer on pricing while we're at it.
By calling or texting, you consent to receive messages from Batchly (AgentMachine LLC). Msg & data rates may apply; msg frequency varies. Reply STOP to opt out, HELP for help. SMS Terms · Privacy