Security

Control access to your company’s data

Servers in Poland, login with a password and a phone code, every change with an author. Below we describe, step by step, how it works: who can see your data, who can get into the system, how to check who changed what, and where GDPR fits in. If your IT person needs more, we will answer their questions or fill in a security questionnaire.

Servers in Poland
The system and the database run on NOXTI's own servers in Poland.
A filter in front of the server
Public connections to NOXTI are routed through Cloudflare. The service filters traffic and helps reduce attacks and unwanted bots.
Password and phone code
A password alone is not enough. For the most important operations the system asks for the code again.
The path every entry to NOXTI takes
  1. 1. Employee in the browseron a computer or on a scanner in the warehouse
  2. 2. Filter (Cloudflare)stops attacks, bots and password guessing
  3. 3. NOXTI server in Polandchecks the password, the phone code and permissions
  4. 4. Your company's dataonly yours, other companies are not visible
Someone tries to reach the server bypassing the filterfor example knows the server's address and goes there directlyaccess restricted

Film · 1:42

How we develop protection for your customers’ data

In this film

The video presents our data protection programme, including features under development. Not all are available to customers. This page describes the current scope and planned changes; availability is confirmed during implementation. Screens contain sample data. Watch on YouTube

Data

One platform, each company's data kept apart

Data access by company and permissions

Orders, products and buyers are assigned to a company. User access depends on the company and granted permissions. Separating data restricts other companies’ access to your orders, products, prices and customers.

Allegro, Zalando and courier credentials under lock

Credentials for marketplaces, shops and carriers are stored encrypted. The decryption key is kept separately from the database. Credentials are masked in the Panel; encryption reduces the risk of disclosure from a database copy alone.

The full buyer address is seen by whoever packs

The company can set it so that only the person packing the parcel sees the buyer's full address, while everyone else sees a shortened version.

Servers in Poland

The system, the database and the files, including labels and documents, run on NOXTI's own servers in Poland. Marketplaces and couriers receive only what is needed to ship a specific order.

Access

Who signs in, from where and for how long is up to the company

Sign-in

Password and phone code

  • You enter the system with a password and a six-digit code from a free authenticator app on your phone, like the one for your bank. A stolen password alone is not enough.
  • In case the phone is lost, everyone gets eight one-time backup codes.
  • For the most important operations, e.g. granting permissions or changing the connection to Allegro or a courier, the system asks for the code again.
  • The company can allow a trusted computer not to ask for the code every day. The password is always required.
Devices

Every computer and scanner separately

  • Every device logs in separately. If a scanner goes missing, you log out only that one. If you suspect someone knows a person's password, one button logs that person out of every device at once.
  • A scanner left on a shelf logs itself out after a set period of inactivity. The company decides after how many minutes and who is exempt.
Permissions

Who can do what, and from where

  • Roles decide who sees orders, who sees prices, who sees settings. Administrator rights can only be granted by someone who has them.
  • The company can restrict a given person's login to the office and the warehouse. An attempt from anywhere else is rejected and recorded. One condition: the office needs a fixed internet address, which your provider can confirm.
  • The login history shows who logged in, when and from where, including failed attempts.
My devicesSample view from the panel
  • Chrome, Windowsofficethis device
  • Scanner, hall Awarehouseactive 2 min ago
  • Safari, iPhoneoutside the company networktrusted device, 30 days
Sign out this deviceSign out everywhere
Sign-in historySample view from the panel
  • Today 07:52Chrome, Windowsoffice
  • Today 06:58Scanner, hall Awarehouse
  • Yesterday 23:14unknown browseroutside the office, rejected
Phone code enabledBackup codes: 8

The device names on these cards are examples. The layout and scope of information are as in the panel.

Change log

Every change to an order, stock level, price or permission has an author

When someone asks why an order has a different address or where a stock correction came from, the answer is in the log, not in guesswork. The log cannot be edited or cleared from the panel.

  • Who changed it, when and from where
  • What exactly changed: the value before and after
  • Whether a person made the change, it came from Allegro or a courier, or the system made it itself
  • The company it concerns sees the entry in its own panel
Order, delivery addressSample entry
Who
Anna K., customer service
When
20.09.2026, 14:02
From where
office, panel
Street
Kwiatowa 5 Polna 12
Postcode
00-001 00-002

GDPR

Buyer data is yours. We only process it

Buyer data is yours

NOXTI uses them only so that the order gets picked, packed and shipped. What we may and may not do with your customers' data is set out in the data processing agreement, the document GDPR requires, which is part of the agreement to use NOXTI.

Data protection officer

The company profile has room for your data protection officer's details, if you have one. The change log is kept for a year by default; the company can shorten that period or keep the log indefinitely.

If data leaked

If buyer data leaks or someone reaches it without authorisation, we inform the company concerned without undue delay: what happened, which data it concerns, what we did. The company decides whether to notify the data protection authority, because it is responsible for its customers' data. We provide the facts and the log.

AI only on request

Buyer data goes to the AI provider only when your company uses AI order checking and runs it for a specific order. Otherwise no buyer data leaves the system in that direction.

Our subprocessors: we choose them and answer for them

Cloudflare
passes connections through to NOXTI and filters out attacks; does not store the database or files
Data centre in Poland
power, connectivity and physical security of the servers; no sign-in to the system
The AI provider
only when the company uses AI order checking; the feature can be left unused

Full list with countries and how it changes: Subprocessors.

On your company's instruction: you connect them, we pass the data

Marketplaces and stores
orders, statuses and tracking numbers, both ways
Carriers
recipient details for the label and parcel tracking
E-mail and SMS on the company's account
buyer notifications sent from your company's account

Attacks from the internet

Public NOXTI traffic passes through a filter

  • Before anyone reaches NOXTI, they pass through Cloudflare. It is a service that filters out attacks, bots and attempts to block the system by flooding it with artificial traffic.
  • We route public NOXTI traffic through Cloudflare. Restricting direct access to the server helps prevent bypassing this protection.
  • Anyone trying to guess passwords is blocked after a series of failed attempts, before they even reach the system.
  • Connections to the NOXTI website and Panel use HTTPS. Encryption protects login and order data in transit.

It is NOXTI that connects to Allegro, Zalando and the couriers, not the other way round. The notifications partners send back to us pass through the same filter as everything else.

Frequently asked questions

What companies ask before going live

Can an employee log into the system from home?
Yes, if the company allows it. For selected people, login can be restricted to the office and warehouse addresses; an attempt from home is then rejected and shows up in the login history.
What if an employee leaves the company?
The administrator disables their account. From that moment the account stops working on every device, including a phone at home where that person was still logged in. Every change they made stays in the log under their name.
What if an employee loses the phone with the codes?
They log in with one of the eight one-time backup codes they received when enabling the phone code, and the administrator sets up their phone again.
Can anyone at NOXTI see our passwords or Allegro credentials?
User passwords are not stored in plain text. Marketplace credentials are encrypted and masked in the Panel. Technical access to the system is restricted to authorised personnel.
What about orders when NOXTI is down?
Once service is restored, we recover orders available from Allegro, Zalando or your shop within the capabilities of their APIs. Recovery depends on how long the provider retains the data, its limits and the permissions on your account.
Do we have to install or open anything in our network?
No. NOXTI runs in the browser, on scanners too. It is NOXTI that connects to Allegro, Zalando and the couriers, not them to your network.
How do I check who changed the address on an order?
In the change log on the order: who, when, from where, and the address before and after the change.
Our IT department wants a security questionnaire and a data processing agreement
The data processing agreement is published on the Documents page. We fill in the questionnaire based on what is on this page, with references to the specific mechanisms. Write to us.

What we are rolling out now

Buyer data protection programme, September 2026

Some marketplaces require the systems that handle their orders to encrypt buyer data, delete it after delivery and record who looked at it. We are rolling this out for every company on NOXTI. It is not live for customers yet: the code is written and tested, and we are switching it on step by step.

Buyer data encrypted in the database

The buyer's name, address, phone and e-mail will be encrypted in the database with a separate key for each company. Anyone who looks into the database bypassing the system will see a meaningless string. Searching by name or phone will keep working.

Buyer data disappears after delivery

The company will set how many days after delivery the buyer's data disappears from the order. Country, order number, products, amounts and tracking number stay. An open return or complaint pauses the deletion, and the order will show that the data was removed and why.

No personal data in technical records

The system's internal technical records will not contain e-mails, phone numbers or addresses. Exported list files, e.g. for Excel, will be deleted after download or after a week at the latest.

A record of who viewed customer data, and alarms

A separate record of who viewed customer data, exported lists and printed labels. The system will raise an alarm on a series of failed logins, a mass export, the phone code being switched off or a login from a new country.

Encrypted disks

Data disks will be encrypted, so a disk pulled out of the server is useless. We will rotate the encryption keys every year, without interrupting the system.

When a given point goes live for customers, we move it up into the description of what works today. This page as of: 20 September 2026.

What is not here

We do not have an ISO 27001 certificate or a SOC 2 report, the certifications large corporations ask about

The points above come from our own work on this system, not from an external audit. We have not yet commissioned an outside firm to attempt a break-in, so-called penetration testing. Anyone who finds a security flaw can report it to hello@noxti.com or through the contact form; we fix it and let you know when the fix is live.