Security and privacy
Every security decision in CHK is enforced in two places — in the app itself and on our servers — so getting past one is never enough.
No business can see anything belonging to another. We don’t stop at the promise: with every release we actually try to reach another business’s data — and make sure the attempt fails.
You sign in with a code sent to your phone, so there’s no password to forget or steal. The code is never stored as-is, so even a leaked copy of our data would hold no valid code.
Permissions come from role and branch together, and apply to every screen and button. A branch manager can’t act in another branch — even over someone more junior.
Every closure is written with its time from our servers, not the device, and is never edited afterwards. Changing the phone’s clock doesn’t hide a delay — it reveals it.
The log is kept permanently, proof photos at full resolution for 24 months, and operational data for 90 days. During an inspection or dispute you freeze what’s relevant, and nothing in it is deleted.
Location is captured at the moment of closing only, and nobody is tracked. Mystery-shopper responses carry no name or number. Photos are collected as task proof, nothing more.
Encrypted in transit between your device and our servers, and encrypted at rest.
We limit repeated login attempts, validate everything sent to us before accepting it, and prevent our pages from being framed by other sites.
We value responsible disclosure. Send us the details and steps to reproduce — we read every report and reply.
security@chk.sa
Fourteen days free, no credit card. Your business is ready in three steps: name and mobile, then industry, then number of branches.