Trust Center
Security you can check, not just believe.
We sell a product whose entire promise is that records cannot be quietly changed. It would be absurd to ask you to take our security on faith. Here is how it works, what is verifiable, and what we have not built yet.
EU only
Hosting and data residency
Append-only
The ledger cannot be edited
Worldline
Certified payment path
Per tenant
Isolation between customers
The security model
Integrity first, because that is what is being attacked.
Most systems protect against outsiders getting in. A sales system also has to protect the record from everyone who is legitimately inside it, including the owner, the staff, and us.
That is why the ledger is append-only and hash-chained rather than a table with an update statement. Each entry carries the hash of the one before it, so removing or altering any entry breaks the chain from that point forward, visibly. There is no administrative path around it. Support cannot quietly fix a number for you, and that is the feature.
What that gives you
- ▪Entries are attributable: staff identity, counter, timestamp
- ▪Corrections are appended with a reason, never silent
- ▪The sequence can be verified, not merely trusted
- ▪An audit becomes a replay rather than a reconstruction
- ▪Anomaly Guard flags void and refund patterns worth a look
The practical measures.
Hosting
European Union infrastructure. Customer data stays in the EU in normal operation, and transfers outside the EEA would require a proper mechanism and notice.
Encryption
Encrypted in transit, and at rest in our hosting environment. Modern TLS on every interface, including the API.
Tenant isolation
Logical separation between customers, enforced at the data layer so a query cannot cross a tenant boundary.
Access control
Individual accounts, role-based permissions, least privilege for our own staff, and administrative access logged.
Payments
Card data is handled by Worldline on certified hardware and never reaches our servers or your device. Read the partnership page.
Backups
Regular backups with restoration tested, so recovery is a rehearsed procedure rather than a hopeful one.
Environments
Development and testing run on separate environments and test data, not on live customer records.
Availability
Offline-first at the counter, so a network problem does not stop you selling. Incidents are posted on the status page while they happen.
Deterministic AI
The assistant reads your sealed data and answers from rules. It does not invent figures, and it cannot reach another tenant's data.
Two-factor authentication
Standard time-based codes from any authenticator app, on back-office accounts. A wrong code costs an attempt rather than sending you back to the password, because a security step people work around protects nobody.
Staff at the counter
Cashiers sign in with a personal PIN that is verified on the terminal, so it still works when the line is down. Every sale, void and refund carries the name of whoever made it, and one that needed authorising names both people: the one who asked and the one who approved.
Privacy and the paperwork
GDPR, in documents you can actually sign.
You are the controller of what happens on your counters. We are your processor, and we work to a written agreement that says exactly that.
When somebody asks what you hold on them
Fizzy can gather everything one shop holds about one person and hand it over, scoped to that shop on purpose: the same person may exist at another business on the platform, and each business is a separate controller with no business reading what the other recorded. The export says out loud what it left out and why, because one that quietly omits something is worse than one that admits it.
Erasure removes what can be removed and tells you what was kept. It is never a hard delete of a row the books depend on: the name comes out, the reference stays, so a Z-report from last March still adds up and simply says who did it in a way that no longer identifies anyone. Your retention obligations for sales records outlive somebody's request, and a system that pretended otherwise would put you in breach of one law while satisfying another.
Sub-processors
We keep the list short and boring: cloud hosting and backup, payment processing through Worldline, email and messaging delivery, error monitoring, and our accounting provider.
The current named list goes out to customers and prospects under evaluation on request, and we give notice before it changes.
Request the current listThe part most trust pages leave out.
We are a small company founded in 2025. Pretending otherwise would be exactly the kind of unverifiable claim this product exists to eliminate.
What we do have is a payment path certified by Worldline, a ledger whose integrity you can verify yourself, EU hosting, and founders who will answer a security questionnaire personally rather than route it to a portal. If your procurement process needs something specific, ask, and we will tell you plainly whether we have it.
If something goes wrong
Told early, told fully.
Service incidents are posted on the status page while they are happening, not summarised comfortably afterwards. If a personal data breach affects your data, we notify you without undue delay, with what we know, what we do not know yet, and what we are doing about it.
Reporting a vulnerability
Write to legal@fizzy.fi with enough detail to reproduce it. Act in good faith, stay away from other people's data, and give us reasonable time to fix it. We will not send lawyers after someone who helps us.
Send us the hard questions.
Security questionnaires, architecture detail, or a call with the CTO. A founder answers, within one business day.