Security
Last updated: 20 September 2026
Account and operational safeguards
Authentication is handled through managed identity services. Sensitive operations require signed-in access, business records are backed up by our managed infrastructure, and access rules are reviewed as the product changes. Store owners remain responsible for choosing strong passwords and removing team members who should no longer have access.
Incident response
We investigate suspected security incidents, contain affected systems and preserve relevant records. Where a personal-data breach creates a legal notification duty, we will notify the Nigeria Data Protection Commission and affected organisations or people without undue delay, following the timelines required by the NDPA and current NDPC guidance.
Store independence
Every table that holds business data carries a store_id, and row-level security is enabled on every one of them. A tailor logged into one store cannot read or write another store's clients, orders, measurements or payments — this is enforced by the database itself, not just by the app's screens.
Role separation
Owners, managers and tailors see different things by design. Tailors work from a database view that never includes prices, costs, payments or balances — those columns simply aren't present in what a tailor's account can query, regardless of what the interface shows.
Public and customer-facing pages
Booking pages, storefronts and group-order links work without an account, but they never expose your client list or order book. Anonymous visitors can only submit new requests (booking, sew, guest updates on their own invite) — they cannot read anyone else's data, and each of those intake forms is rate-limited to stop automated spam.
Support access
Bethjay staff cannot open a store's data by default. An owner must explicitly grant time-limited access (24 or 72 hours) from Settings, it expires automatically, can be revoked at any time, and every access is written to an audit log the owner can see.
Payments
Jaylor never stores card numbers. Customer payments are designed to route to a store's own payment account, never through a shared Jaylor balance.
Transport and headers
All traffic is served over HTTPS with HSTS enabled, and responses set standard hardening headers (no content-type sniffing, no framing by other sites, a restrictive referrer policy).
Responsible disclosure
If you believe you've found a security issue, email info@jaylor.com.ng rather than testing against live customer stores. Include enough detail for us to reproduce the issue. We aim to acknowledge reports within 2 business days.
Jaylor is a product of Bethjay Global Enterprise Limited, RC 3283706 — FCT Abuja, Nigeria.
