SEC.00 / SECURITY
Security is the product,not a feature of it.
Our clients hold money, records, identities, and privileged information. The model below is what we implement — not what we market.
S.01Deployment & residency
Client-controlled infrastructure or a dedicated sovereign environment. No shared multi-tenant store, no vendor-side copy of client content.
S.02Identity & access
Multi-factor authentication with our own TOTP application. Short-lived, rotated tokens with server-side revocation. Role-based permissions enforced at the API layer.
S.03Transport & storage
TLS for all traffic. Encryption at rest for databases and object storage. Object access issued as scoped, time-limited grants. Keys in managed secret storage with a defined rotation procedure.
S.04Platform hardening
Anti-replay protection and rate limiting at the gateway. Network segmentation between application, data, and management tiers. Datastores reachable only from the application network, never from the public internet.
S.05Monitoring & response
Centralised logging and metrics with alerting on authentication failures, error signatures, and service health. Defined incident response. Continuous dependency auditing with a documented patch cycle.
S.06Continuity
Backups with tested restore procedures and defined recovery objectives. Every change moves through separate staging and acceptance environments before production.
SEC.01 / COMPLIANCE
Compliance obligations do not stop at encryption.
Residency
Satisfied structurally. No cross-border transfer to review, no sub-processor chain to disclose.
Retention & supervision
All records retained server-side under your policy — searchable, exportable, with configurable retention and legal hold. Supervisory visibility is itself permission-gated and logged.
Auditability
Administrative actions, access grants, authentication events, and record changes logged with actor, timestamp, and context.
Access governance
Least-privilege roles, separation of duties, joiner–mover–leaver processes, periodic access review with per-user permission reporting.
Regulatory alignment
Built to support UAE data protection law and sector requirements in financial services, healthcare, and government; maps onto GDPR-style principles for international operation.