Separation between businesses
ulostock is multi-tenant. Every business operates in its own workspace with its own data, users and configuration, and records carry the identity of the business that owns them. That ownership is enforced where the data is read, not only in the interface — so a request cannot reach another business’s records by changing what it asks for.
Authentication
Sign-in uses OAuth2 with bearer tokens. Passwords are stored hashed and are never recoverable in readable form; password strength requirements are configurable for your account. Sessions expire, and tokens are refreshed rather than held indefinitely.
A user assigned to more than one branch can move between them without signing out, and the branch they are working in is carried in their session rather than chosen by the browser.
Authorisation
What a signed-in user can do is governed by role-based permissions covering every area of the system — staff, products, inventory, purchasing, sales, returns, transfers, expenses, reports, dashboard and workflow. Permissions are checked on the server for each operation, not merely used to hide buttons.
Staff are additionally scoped to the branches they are assigned to.
Traceability
Records carry who created them and who last changed them. Product changes are logged, stock movements are recorded as their own history, and approvals keep a trail of who approved or rejected what and when. Where an approver has delegated their authority, the delegation is a record rather than an arrangement.
Data in transit and at rest
Traffic between your browser and the service is encrypted in transit. Files you upload — receipts and product images — are held in managed object storage rather than on application servers.
Payment card details are handled by our payment providers and do not reach our systems.
Reporting a vulnerability
If you believe you have found a security vulnerability, email hello@ulostock.com with enough detail to reproduce it. We will acknowledge your report and keep you informed while we investigate.
Please give us a reasonable opportunity to fix an issue before disclosing it publicly, and please do not access, modify or delete data belonging to anyone else while investigating. We will not pursue a researcher who reports in good faith and within those bounds.
What this page does not claim
We describe here what the product does. We do not claim a certification we do not hold. If you need specific assurances — a particular standard, a penetration test report, a data processing agreement, or confirmation of where your data is hosted — ask us and we will tell you where we stand.