Sign-in is token-based (JWT), so a session is never a raw password sitting in a cookie. Staff accounts get scoped permissions set by the firm's admin — for example, a counter-sales role can use Sales Mode and inventory without seeing cash flow totals or firm-wide settings.
Inventory, invoices, CRM, cash flow, karigar jobs and kitty schemes are cloud-synced, not stored only on one device.
PAN, invoice totals and CGST/SGST/IGST splits are computed and stored per compliance requirements, not exposed beyond what invoicing needs.
Only reads and writes the catalogue/stock fields required to keep inventory in sync — no unrelated store permissions requested.
Each firm's data is scoped to its own account — inventory, customers, and financial records for one firm are not visible to another, even though CaratOS runs as shared infrastructure across firms.
If you believe you've found a security issue, email chirant@izaragems.com directly rather than filing it publicly. We'll acknowledge and follow up.