Where your data lives, who can reach it, and what your IT team needs.
Last updated 29 September 2026
This page is for business owners and their IT teams. It covers Madar OS and Madar POS. Everything on it is how Madar works today. Where something is not built yet, it says so.
For IT teams: what to allow on your network
Your own private workspace
Every customer gets a workspace of their own. It runs as its own set of containers, with its own database and its own private network on the server. No two customers share a database, and one workspace cannot reach another.
Customer workspaces run on a server of their own, apart from the servers we use for our own work. Today that server is in Oracle Cloud's Frankfurt region, in Germany, and Oracle encrypts its disks at rest. A Gulf region is on the way; until it opens, nothing is hosted in the Gulf. Our team has administrative access to these servers, so it can read a workspace's data. We use that access to keep them working and to restore a backup.
Encrypted connections only
- Every workspace has its own address and its own TLS certificate, issued by Let's Encrypt and renewed automatically.
- A visit over plain HTTP is sent straight to HTTPS. Browsers are also told to use HTTPS only for this address for a year (HSTS). The website does the same.
- Every page of a workspace carries security headers: no other site can frame it, scripts load only from the workspace's own address, no address is passed on to other sites, and camera, microphone, location, payment and USB access are switched off.
Signing in
- Passwords are at least 10 characters. Madar keeps only a scrypt hash of each one, never the password itself.
- After five wrong attempts, sign in closes for 15 minutes for that network address, and for that name on any browser that has not signed in with it before. The count is kept in memory, so a restart of the workspace clears it.
- Two step sign in with an authenticator app on your phone. The owner turns it on in Settings; from then on, sign in asks for the six digit code too.
- The sign in cookie cannot be read by scripts on the page and travels only over HTTPS. A session ends after 30 days unused, and always after 90.
- Forgot your password? A reset link goes to the owner's email. It works once, for 30 minutes. A reset signs out every device and turns off the authenticator app, so keep that email account safe too.
- The first sign in link, emailed when your workspace is made, works once. It lasts seven days unless we extend it for you.
Who can do what
The owner decides who signs in, and each person has their own login. With Madar POS:
- A cashier login opens the cashier screen and nothing else, at its own branch.
- A manager login also opens the shop's admin. From the start a manager can run items, prices, costs, stock, suppliers, customer accounts, discounts and returns, and the owner can turn any of these off. Voiding a sale, changing settings and adding cashier logins stay off until the owner turns them on.
- The owner can do everything. Cashier and manager logins cannot open Madar's assistant.
These rules are checked by the server on every request. They are not only hidden buttons.
Nightly encrypted backups
Every night, each workspace (its database, its files and its memory) is packed into one archive and encrypted before it leaves the server. The key that opens the archives is kept on no server, so neither server can read a backup. Each archive is kept for seven days on our servers, and a copy is stored in Oracle Cloud Object Storage in Frankfurt, apart from the server that runs your workspace.
We have checked that backups open. On 29 September 2026 we decrypted the backups of our own test workspaces and restored their databases into a spare database, and every table and every row came back. A full restore of a live workspace has not been rehearsed yet; that is on the way.
Payments
Plans bought on this website are paid through Paddle, our Merchant of Record. Paddle takes your card or payment details directly; card numbers never reach Madar. Paddle signs every message it sends us, and Madar checks the signature before it acts on one. An order agreed with us directly is invoiced by us and paid by bank transfer.
At the counter, Madar POS records how much of a sale was paid by card. The card itself goes through your own card machine; Madar never sees it.
Your data is yours
- Download my data, in Settings, gives the owner one archive: files, knowledge, memory, chats, setup, and records such as clients, deals, payments, invoices and books. With Madar POS it also holds items, sales, returns and refunds, shift counts, deliveries, stock counts, transfers between branches, customer accounts and supplier balances.
- Delete my workspace, in Settings, sends us your request, confirmed with your password. We delete the workspace within 30 days and email you when it is done. Its backups on our servers age out after about a week. Nothing removes its backup copies in Object Storage automatically yet.
- We do not sell, rent or trade any data. If something ever goes wrong with your data, we tell you within 72 hours of learning of it, as our privacy policy says.
AI, as it really is
Madar POS runs on rules, not AI. Every price, total, VAT amount, stock level, alert and balance is worked out by fixed rules in your workspace's own database and server.
Madar's assistant is a separate part. Cashier and manager logins cannot open it, and the shop works without it. When the owner asks it something, the question and the parts of the business it needs to answer are sent to Anthropic, the AI provider named in our privacy policy, which writes the answer. Under Anthropic's commercial terms that is not used to train their models.
It asks before it sends. The assistant waits for the owner's yes before it sends a message on your behalf or changes anything in a connected service. The one thing it does there without asking is save a draft in your own mailbox, which sends nothing. Its answers are written by AI and can be wrong, so check anything that matters.
For IT teams
Madar runs in a web browser. It needs nothing on your network except the addresses below.
Addresses to allow
madar-os.com: the website, checkout and support.*.madar-os.com: customer workspaces. Each workspace has one address of its own, such asyourcompany.madar-os.com.
Ports and protocols
- HTTPS on TCP port 443 is all Madar needs.
- Chat with the assistant uses a secure websocket (
wss://) on the same address and the same port. - Port 80 only redirects to HTTPS.
Nothing to install
- Madar opens in a current web browser on a computer, tablet or phone.
- For Windows counters there is an optional installer, from Install on the cashier screen or Install on this computer in the admin portal. It is a small script file, plain text you can read before you run it, and it installs no program. It puts shortcuts on the desktop that open Madar in Microsoft Edge, in an Edge profile of their own, fetches their icons from your workspace, can make the receipt printer the default printer (and stop Windows changing the default by itself), and can open the cashier screen when the computer starts.
- Sign in links, password resets and approvals come from
noreply@madar-os.com. Please let it through your mail filter. - Our mail is signed with DKIM, and
madar-os.compublishes SPF and DMARC records.
Optional
- Some pages load fonts from
fonts.googleapis.comandfonts.gstatic.com. If those are blocked, Madar still works with the computer's own fonts. - Buying or changing a plan uses Paddle's checkout, from
paddle.com. - Notifications, if someone turns them on, arrive through the browser's own push service, as they do for any website.
A new domain
madar-os.com was registered on 27 September 2026. Some filters
block domains in their first weeks. If yours blocks Madar, allow the two addresses above.
Report a security problem
Write to security@madar-os.com. Tell us what you
found and how to see it, and give us time to fix it before you share it with anyone else. Questions
from your IT team go to the same address. The same contact is published, machine readable, at
/.well-known/security.txt on this website.
The same file on every workspace address is on the way.