Skip to content

Security

Protecting salon and client data is foundational.

Salon OS applies layered application, access, transport, deployment and recovery controls. Formal certifications are only published after independent verification.

01

Tenant-scoped access

Application requests are authenticated and operational data paths are scoped to the active salon context.

02

Role-based permissions

Owners, managers, front desk and stylists receive permissions appropriate to their responsibilities.

03

Encrypted transport

HTTPS, secure session settings and modern browser security headers protect data in transit.

04

Recovery controls

Release restore points, backups and rollback procedures support operational recovery.

05

Controlled releases

Compatibility checks, preflight validation, checksums and post-install verification reduce deployment risk.

06

Operational traceability

Administrative and platform operations are recorded to support review and troubleshooting.

Responsible disclosure

Report a suspected security issue privately to security@cabeloos.com. Do not access, alter or retain data that does not belong to you.

Verification statement: This page describes implemented design controls and operating practices. It does not claim SOC 2, ISO 27001, PCI DSS or other certification unless expressly stated.