Fiscal security goes beyond a password. Data must be protected in storage, transmission and later review through encryption, digital signatures and traceable actions.

Encrypted ATK communication

Communication between SEF and the ATK Information System should use the defined secure and direct protocols, protecting data in transit.

Signing the receipt

The digital signature is tied to receipt content and represented in the QR code, making later alteration detectable.

Security inside the business

Roles, operator PINs and audit records restrict sensitive actions and show who performed them.

  • Role-based access.
  • Sensitive action logs.
  • Tested backup and recovery.
  • Controlled application updates.

Security begins with identity and access

Each operator should use an individual account. Roles determine what they can see and do, while sensitive actions—corrections, configuration changes or report access—should be logged. Shared passwords remove that accountability.

Review access when an employee changes role or leaves. Old permissions should not remain active by accident.

Technical and organizational controls

Encryption and digital signatures matter, but they do not replace backups, updates, device control and staff training. Durable security is layered.

  • Individual accounts and least privilege.
  • Audit trail for critical actions.
  • Backups with a restore test.
  • Controlled devices and updates.
From the rule to daily operations

Pre-launch check

Use this guide as a basis for discussion with your team and software provider. The actual setup depends on your activity, locations and internal procedures.

  1. Define items, tax rates, prices and payment methods.
  2. Set operator roles and shift responsibilities.
  3. Test sales, corrections, offline work and reports.
  4. Document the workflow and train staff before activation.
FAQ

Practical questions

Should every operator have a separate account? +

Yes. Individual accounts enable role-based access and keep actions attributable in the audit trail.

Is an untested backup sufficient? +

No. A business should know that the backup can be restored and how long operational recovery takes.

Is a digital certificate required for every installed SEF? +

Yes. The instruction requires a certificate for each SEF installed at a point of sale, and its private key must be kept highly secure and confidential.

easyPos Kosovo

Want to see easyPos in your business?

Tell us your type of activity and sales locations. We will show you a tailored workflow.

Request a demonstration