Security

Access, isolation, and accountable operations.

Quelboo is designed around role-based access, server-side authorization, tenant isolation, payment-provider verification, audit logging, and responsible deployment practices.

Role-based access

Customer, business, staff, and admin experiences are separated by role.

Server-side authorization

Sensitive actions are intended to be enforced by backend contracts, not only by the UI.

Tenant isolation

Business data is organized so one tenant cannot browse another tenant’s private records.

Payment verification

Payment-provider verification and webhook-driven confirmation are part of the platform design.

Audit logging

Elevated and operational actions are designed to leave an accountable trail.

Account security

Password reset, email confirmation, and invitation flows use dedicated production routes.

Admin MFA

Administrative surfaces present multi-factor enrollment and challenge states.

Responsible deployment

Secrets stay off the public site. Support remains available at support@quelvaro.com.