Why these controls matter
Security features are only useful if they reduce a real business risk
Salon Manager combines multiple layers of protection so access to client and business data does not depend on a password alone. The aim is to make unauthorised access harder, reduce avoidable mistakes and give the salon more control over who can access the system and from where.
Risk: a password is stolen or guessed
Two-factor authentication adds another barrier
A password on its own should not be enough to gain access. Two-factor authentication adds a second verification step, reducing the risk that a compromised password immediately becomes a compromised account.
Risk: staff can see or change more than they need
User access levels limit unnecessary access
Role-based permissions help the business decide which users can view or change sensitive areas. That supports clearer responsibilities and reduces the risk created by giving every user unrestricted access.
Risk: someone tries to log in from an unapproved device
Device control adds another layer of approval
The business can control which devices are approved to access Salon Manager. If somebody tries to sign in from a new or unapproved device — for example from home — access can require approval before the device is trusted.
Risk: data is exposed if systems or traffic are intercepted
Encryption helps protect sensitive information
Encryption helps protect salon and client data in supported storage and transmission scenarios, reducing the risk that information can be read if it is intercepted or accessed without authorisation.
Risk: security controls are assumed rather than evidenced
Cyber Essentials gives independent assurance
Salon Manager is Cyber Essentials certified, providing independent evidence that recognised core technical controls are in place to help protect against common cyber attacks.
Risk: weaknesses exist but nobody is actively looking for them
Independent penetration testing looks for vulnerabilities
Annual penetration testing uses realistic attack techniques to identify weaknesses that may need attention, rather than relying only on internal assumptions about security.