Kushify
Security

Built for the audit,
not just the demo.

Cannabis platforms handle regulated data — IDs, medical records, transaction histories. We treat security as foundational, not promotional. Here's what's in production today.

Talk to security →See compliance
Certifications

What we comply with.

SOC 2
Type II controls in production; report available to Enterprise customers under NDA
GDPR
Customer data export and deletion tooling
CCPA
California Consumer Privacy Act compliance
PCI DSS
We don't store card numbers — handled by your processor (Aeropay, Sprout, etc.)

Encryption in transit

TLS 1.3 on all customer-facing endpoints. HSTS preload-eligible. No HTTP fallback.

Encryption at rest

AES-256 disk encryption on every database and object store. Backups encrypted with separately-managed keys.

Row-level security

Database-level scoping ensures one operator's data never crosses into another's. Multi-site cross-storefront access is policy-enforced, not application-enforced.

Audit logging

Every status transition, refund, override, and verification decision writes to an immutable history table. Available for export to your SIEM.

Least-privilege access

Engineering access to production is JIT-granted, time-bounded, and logged. Console access is two-factor required across all admin tools.

Backup + recovery

Continuous backups with 30-day point-in-time recovery. Quarterly disaster recovery drills. Documented RTO/RPO available on request.

Dependency scanning

Automated scanning of all third-party dependencies. CVE alerts patched within SLAs based on severity.

Penetration testing

Annual third-party penetration test by a recognized firm. Findings remediated; the latest report is available to Enterprise customers under NDA.

Responsible disclosure

Security researchers can report vulnerabilities to [email protected]. We respond within 48 hours and don't litigate good-faith research.

Reporting

Found a vulnerability?

We treat security researchers as partners. Email [email protected] with reproduction steps. We respond within 48 hours and do not pursue legal action against good-faith researchers who follow responsible disclosure.

For general security questions, contact us at [email protected] or call (888) 836-6322.

Ready when you are

Want our full
security package?

Enterprise customers get the SOC 2 report, penetration test summary, and architecture review under NDA. Reach out to get started.

Request package →See compliance