Log in
Talk about my operation

Technology · Trust

Information security

Security travels with the data, from the point of sale to the repository.

The challenge

In a chain, sensitive data is everywhere — sales, customer, tax, financial — and the number of people with access grows with the locations. When control relies on trust in the team, rather than permissions in the system, security stops scaling at the same pace as the operation.

What this costs

Access that's too broad is a risk of leaks and errors; too rigid, and it blocks the people who need to work. And under the LGPD, customer data now requires proper handling and accountability — exposing it stopped being an oversight and became a liability.

Access is governed by granular permissions tied to the chain's hierarchy: each person sees and does what their role allows, and every action has an author. Customer data is handled under the LGPD and remains the customer's. Security is part of the architecture, not a layer bolted on top.

Layer 03

Ecosystem and data

It sits alongside the data, in the data layer: access control and processing under LGPD follow the information wherever it lives, instead of protecting only the front door.

What this delivers

Granular permission-based access

What each person sees and does is defined by role and location, not by trust.

Audit trail

Every sensitive operation has an author and a record, which makes the history auditable.

Segregation by location and brand

One location can't see another's data beyond what the chain's governance allows.

Customer data under LGPD

Personal data is handled in accordance with LGPD, with its own privacy channel.

Data ownership

The operation's data belongs to the chain — the platform stores and delivers it, it doesn't hold onto it.

Separate certification environment

Integrations and changes are tested outside of production, with test data, before touching the operation.

Conversation with
  • Corporate ERP
  • BI

Frequently asked questions

How is data access controlled across a large chain?

Through granular permissions tied to the group → brand → location hierarchy. Each person's role defines what they can see and change, and one location can't access another's data beyond what the chain authorizes.

Does the data belong to EPOC or to the client?

The customer's. The platform exists so the operation's data is available to the chain — including for export — and not locked to the vendor.

How does the platform handle LGPD?

Personal data is handled in accordance with LGPD, with a dedicated privacy channel ([email protected]) for data subjects and the data protection officer. Specific compliance requirements are detailed during the sales process.

Talk to a specialist

Your operation has grown. Is your technology ready?

How many locations, what stack is already running, what needs to be integrated, and what the rollout would look like.