Security & Liability Disclosure
Version 2026-07-06 · Required acknowledgment before any tier
Security measures (defense in depth)
- Authentication: bcrypt password hashing, leaked-password blocking, mandatory 90-day rotation, optional TOTP 2FA
- Database: PostgreSQL row-level security — each user isolated
- Encryption: TLS in transit; AES-256-GCM for bank secrets at rest; SHA-256 for audit hashes
- Media: Private inventory photos — signed URLs expire
- Ledger integrity: Append-only sales history
- Network: HTTPS-only webhooks, SSRF protections, security headers (CSP, HSTS where configured)
- Monitoring: Hashed audit trail; platform security review every 30 days
- Auto-sync: Scheduled bank/store sync with user consent at account setup
What “military-grade” means in practice
Marketing terms vary. PowerABL implements industry-standard commercial security aligned with NIST guidance: strong cryptography (AES-256, SHA-256), least-privilege access, and multi-layer controls. No consumer SaaS can guarantee zero risk; we do not claim immunity from all attacks.
What we cannot guarantee
No system is 100% breach-proof. You acknowledge internet services carry inherent risk. You are responsible for device security, phishing awareness, and credential confidentiality.
Tax & legal disclaimer
PowerABL provides estimates and worksheets only. We do not file taxes on your behalf. Churches, nonprofits, and businesses must consult qualified professionals for Form 990, UBIT, sales tax, and payroll.
Liability
Full release: Liability Release & Waiver. By accepting, you hold operators harmless except where prohibited by law.