Trust + security

The pawn industry's most auditable stack

Most legacy pawn systems weren't built encryption-first β€” customer DOB and DL numbers often sit unprotected, and few can tell you who viewed which record. ODIN encrypts every PII column at rest, audits every PII read, and lets you export all of your data anytime β€” your records are never held hostage.

How ODIN protects your shop's data

πŸ”’

Encryption at rest

Every PII column (DOB, DL number, DL state, address, SSN fragment) is encrypted at rest with authenticated column-level encryption (AES + HMAC-SHA256). Searchable lookups use an HMAC-SHA256 hash sidecar so 'is this a returning customer?' doesn't decrypt every row. A stolen database file yields ciphertext, not an identity-theft pack.

πŸ“œ

Audit trail on every PII view

Every read of a customer's DOB, DL, or address writes an audit_log entry with employee ID, IP, user-agent, and timestamp. State examiner asks 'who looked at this customer's record?' β€” we have the answer.

πŸ›‘οΈ

Pre-hoc compliance

Form 8300, OFAC, MLA, ATF 4473, CDD, GLBA, TCPA β€” all checked BEFORE the operator commits a transaction. Compliance Copilot dismissals are also logged so override patterns surface.

πŸ”

PCI scope: SAQ-A

Square handles every card-present + card-not-present transaction. We never touch a primary account number (PAN). PCI assessment is the cheapest tier (SAQ-A).

πŸ”

Backup + disaster recovery

Automated nightly snapshots with a verified off-site copy β€” to a USB/NAS path, a synced cloud folder, or your own S3-compatible target β€” plus a documented, tested restore runbook. Off-site copies inherit the encryption of the destination you choose.

πŸ”

No lock-in

Your data is yours. One-click export of customers, tickets, inventory, payments, and audit logs anytime, plus a documented exit path. ODIN is proprietary, but never a black box to you β€” no hostage situation, ever.

Twelve federal regulations covered

Every regulation that touches a pawn transaction. Mature means built and validated end-to-end ahead of our July 1, 2026 go-live. Partial means the framework exists, last 10% on the roadmap.

RegulationStatusNotes
Form 8300 (26 USC Β§6050I)MaturePre-hoc detection + structuring band (31 USC Β§5324)
OFAC SDN (31 CFR Part 501)MatureAuto-screen on every customer + transaction
MLA / SCRA (10 USC Β§987)PartialMLA 36% MAPR cap + SCRA active-duty gate built; production DoD/DMDC API key provisioning in progress
ATF 4473 + Bound Book (18 USC Β§923(g))MatureA&D entries + 4473 capture + eForm metadata
GLBA Safeguards (16 CFR Part 314)Partial7y log retention + customer redaction; ISP review pending
GLBA Privacy Rule (16 CFR Part 313)MatureAnnual privacy notice + right-to-cure
TILA APR disclosureMatureAPR computed + included on every pawn ticket
TCPA SMS opt-inMatureDisclosure snapshot + STOP keyword + audit
CDD Rule (31 CFR Β§1010.230)MatureID-state vs address-state mismatch detection
BSA / SARPartialFramework exists; SAR filing pipeline manual
ECOA Reg B (15 USC Β§1691)PartialPending-notices framework built; adverse-action notice generation on the roadmap
CPSC recalls (15 USC Β§2068)MatureRecall list integration on inventory intake

Every third-party service that touches your data

For DPA / GLBA disclosure purposes. We update this list any time we add or remove a sub-processor; customers are notified by email 30 days before any change.

Vercel
Hosting (cloud broker + marketing)
US (default)
Neon
Postgres database (Cloud tier only)
US East
Cloudflare
DNS + email routing + R2 storage
Global edge
Square
Payment processing (in-store + online)
US
Anthropic
AI inference (accounting copilots, Claude; BYO key option available)
US
Groq
AI inference (storefront assistant + online offer estimator)
US
Google (Gemini)
AI inference (photo item identification, vision)
US
Twilio
SMS (dunning, customer notifications)
US
Better Stack
Uptime monitoring + incident alerts
US / EU

Where we're going

Now
  • Authenticated PII encryption (AES + HMAC) shipping
  • Money columns to integer cents (PR #83)
  • One-click data export + documented no-lock-in exit
  • Compliance Copilot covering 7 federal regulations pre-hoc
Q3 2026
  • SOC 2 Type II readiness assessment (gates Cloud Enterprise tier)
  • Outside pen-test before public launch
  • Multi-state expansion: NC + SC + VA + GA + TN
  • Documented Information Security Program (ISP) per GLBA Safeguards Β§314.4
2027
  • SOC 2 Type II audit window opens (6-month evidence period)
  • SOC 2 Type II report Q3
  • Customer-facing public status page
  • Bug bounty program

If something goes wrong, we tell you within 72 hours

Our incident response policy follows GLBA Safeguards Rule Β§314.4 + state breach-notification statutes (NC GS Β§ 75-65 + 49 other states). Customers affected by any incident involving their data get notified within 72 hours, with a full post-mortem within 30 days.

Security disclosures
security@odinpawn.com
General contact
getodin@odinpawn.com
PGP key
On the roadmap
Trust + security β€” ODIN Β· ODIN