Skip to content
Security

Security and trust

Afrastic is designed for gyms that handle member identities, payments, attendance records, staff access, and communication history every day.

Last updated / June 29, 2026

[01]

Access control

  • Role-based user access for platform, partner, chain, gym admin, receptionist, trainer, and member-facing workflows.
  • Scoped gym context for multi-gym and chain users where configured.
  • Optional two-factor login flows for staff accounts.
  • Administrative controls for user lifecycle, password resets, account state, and impersonation governance where enabled.
[02]

Tenant separation

Afrastic is built around gym tenancy. Operational records such as members, billing, attendance, communications, settings, reports, and staff activity are scoped to the relevant gym or chain context.

[03]

Auditability

  • Security events and audit logs for sensitive platform activity.
  • Activity history surfaces for platform operators and administrators.
  • Communication logs for templates, sends, delivery status, and member preferences.
  • Billing and receipt records designed to support front-desk reconciliation.
[04]

Application security

  • Authenticated admin access with token validation and protected role paths.
  • Password reset and profile-security workflows.
  • Server-side authorization checks across core admin, gym, communication, billing, and security modules.
  • Operational monitoring surfaces for database, object storage, messaging, email, metrics, backups, and maintenance mode.
[05]

Data protection

  • Backups and restore operations are treated as operations controls, not public marketing guarantees unless written into a customer agreement.
  • Uploaded member and gym assets are handled through storage services with signed access patterns where configured.
  • Biometric attendance stores device/member mapping and attendance events. Afrastic does not store fingerprint or face templates in the first release plan.
[06]

Responsible disclosure

If you believe you found a security issue, email [email protected] with a clear description, reproduction steps, affected URL or account context, and your contact details. Do not access, alter, delete, or exfiltrate customer data while testing.

[07]

Customer responsibilities

  • Use strong passwords and enable 2FA where available.
  • Remove staff access when people leave the gym.
  • Assign the least privileged role that still lets a person do their work.
  • Review audit logs, communication permissions, and member consent settings regularly.