Home / Legal & Trust / Trust Center

Trust Center

Security you can check, not just believe.

We sell a product whose entire promise is that records cannot be quietly changed. It would be absurd to ask you to take our security on faith. Here is how it works, what is verifiable, and what we have not built yet.

EU only

Hosting and data residency

Append-only

The ledger cannot be edited

Worldline

Certified payment path

Per tenant

Isolation between customers

The security model

Integrity first, because that is what is being attacked.

Most systems protect against outsiders getting in. A sales system also has to protect the record from everyone who is legitimately inside it, including the owner, the staff, and us.

That is why the ledger is append-only and hash-chained rather than a table with an update statement. Each entry carries the hash of the one before it, so removing or altering any entry breaks the chain from that point forward, visibly. There is no administrative path around it. Support cannot quietly fix a number for you, and that is the feature.

What that gives you

  • Entries are attributable: staff identity, counter, timestamp
  • Corrections are appended with a reason, never silent
  • The sequence can be verified, not merely trusted
  • An audit becomes a replay rather than a reconstruction
  • Anomaly Guard flags void and refund patterns worth a look

The practical measures.

Hosting

European Union infrastructure. Customer data stays in the EU in normal operation, and transfers outside the EEA would require a proper mechanism and notice.

Encryption

Encrypted in transit, and at rest in our hosting environment. Modern TLS on every interface, including the API.

Tenant isolation

Logical separation between customers, enforced at the data layer so a query cannot cross a tenant boundary.

Access control

Individual accounts, role-based permissions, least privilege for our own staff, and administrative access logged.

Payments

Card data is handled by Worldline on certified hardware and never reaches our servers or your device. Read the partnership page.

Backups

Regular backups with restoration tested, so recovery is a rehearsed procedure rather than a hopeful one.

Environments

Development and testing run on separate environments and test data, not on live customer records.

Availability

Offline-first at the counter, so a network problem does not stop you selling. Incidents are posted on the status page while they happen.

Deterministic AI

The assistant reads your sealed data and answers from rules. It does not invent figures, and it cannot reach another tenant's data.

Two-factor authentication

Standard time-based codes from any authenticator app, on back-office accounts. A wrong code costs an attempt rather than sending you back to the password, because a security step people work around protects nobody.

Staff at the counter

Cashiers sign in with a personal PIN that is verified on the terminal, so it still works when the line is down. Every sale, void and refund carries the name of whoever made it, and one that needed authorising names both people: the one who asked and the one who approved.

Privacy and the paperwork

GDPR, in documents you can actually sign.

You are the controller of what happens on your counters. We are your processor, and we work to a written agreement that says exactly that.

When somebody asks what you hold on them

Fizzy can gather everything one shop holds about one person and hand it over, scoped to that shop on purpose: the same person may exist at another business on the platform, and each business is a separate controller with no business reading what the other recorded. The export says out loud what it left out and why, because one that quietly omits something is worse than one that admits it.

Erasure removes what can be removed and tells you what was kept. It is never a hard delete of a row the books depend on: the name comes out, the reference stays, so a Z-report from last March still adds up and simply says who did it in a way that no longer identifies anyone. Your retention obligations for sales records outlive somebody's request, and a system that pretended otherwise would put you in breach of one law while satisfying another.

Sub-processors

We keep the list short and boring: cloud hosting and backup, payment processing through Worldline, email and messaging delivery, error monitoring, and our accounting provider.

The current named list goes out to customers and prospects under evaluation on request, and we give notice before it changes.

Request the current list

The part most trust pages leave out.

We are a small company founded in 2025. Pretending otherwise would be exactly the kind of unverifiable claim this product exists to eliminate.

ISO 27001 certificationNot held today
SOC 2 reportNot held today
Independent penetration test reportAvailable to customers when completed
Formal contractual uptime commitmentBy written agreement, not by default

What we do have is a payment path certified by Worldline, a ledger whose integrity you can verify yourself, EU hosting, and founders who will answer a security questionnaire personally rather than route it to a portal. If your procurement process needs something specific, ask, and we will tell you plainly whether we have it.

If something goes wrong

Told early, told fully.

Service incidents are posted on the status page while they are happening, not summarised comfortably afterwards. If a personal data breach affects your data, we notify you without undue delay, with what we know, what we do not know yet, and what we are doing about it.

Reporting a vulnerability

Write to legal@fizzy.fi with enough detail to reproduce it. Act in good faith, stay away from other people's data, and give us reasonable time to fix it. We will not send lawyers after someone who helps us.

Send us the hard questions.

Security questionnaires, architecture detail, or a call with the CTO. A founder answers, within one business day.