Security
Security facts, not badges
We do not hold security certifications today and will not display any we have not earned. Below is what is implemented and what is planned.
Implemented
Built- Each organisation's records are isolated with database row-level security on every exposed table
- Action-based permissions checked on the server for every read and change
- Organisation ownership cannot be changed on existing records
- Audit events for organisation creation, enquiry creation and project conversion
- Idempotent enquiry-to-project conversion with version checks
- Website enquiries are insert-only for visitors and never publicly readable
Planned
Not yet- Private file storage with signed, expiring links
- Owner/admin multi-factor authentication
- Two-tenant refusal test suite across APIs, files, search and workers
- Backup restore rehearsal
- Published subprocessor list and processing regions
Hosting and processing regions will be confirmed before launch. We do not claim UAE-only processing.