Security
Last updated: September 10, 2026
We know you're trusting OneGemmywith real business data — sales, customers, inventory, and finances. Here's a plain look at how we protect it.
Password security
Passwords are never stored in plain text. They're hashed with bcrypt before being saved, so even we can't read them.
Token-based authentication
Access to your account is controlled with short-lived authentication tokens, so a leaked token doesn't grant indefinite access.
Tenant data isolation
Every business's data is scoped to that business at the data layer. Our engineering rules treat any cross-tenant data access as a bug to be prevented, not a feature.
Encrypted in transit
OneGemmy is served over HTTPS, so data moving between your browser and our servers is encrypted.
Infrastructure
OneGemmy runs on managed cloud infrastructure rather than self-hosted servers, so the underlying hardware, network, and database are operated by established infrastructure providers.
Our approach
We're a growing team building OneGemmyfor businesses across East Africa, and security is something we invest in continuously rather than treat as a one-time checklist. If you have specific security or compliance requirements for your business, reach out — we're happy to talk through what we support today and what's on our roadmap.
Report a concern
If you believe you've found a security issue, please email us at info@gemmyconnect.com with details. We take reports seriously and will follow up directly.