Security

How your documents are protected

This page describes what is actually implemented. Where something is not in place, it says so.

In place today

Tenant isolation

Every document, key and result is scoped to one tenant. Cross-tenant reads are structurally prevented and covered by automated tests.

API key handling

Keys are generated server-side, shown once, and stored only as SHA-256 hashes. A key can be disabled instantly.

Password security

Passwords are bcrypt-hashed. Repeated failed logins lock the account temporarily.

Email and phone verification gate

Accounts cannot sign in until the email address is verified, and scanning and API keys open only after the phone number is verified too.

WhatsApp two-factor

Accounts with a verified phone receive a WhatsApp one-time code at sign-in.

Hash-chained audit log

Significant actions are appended to a chained log, making silent changes detectable.

Database backups

A database backup is taken automatically before every deployment, before any migration runs.

Platform access control

Internal business dashboards are restricted to named Mahad staff accounts — a customer account can never reach them.

What we do not claim

No third-party certification. We hold no ISO 27001, SOC 2 or equivalent audit, and we do not claim certified GDPR compliance.

No uptime SLA. No contractual availability guarantee is offered today.

Off-site backup is not yet enabled. Backups are stored on the same infrastructure as the service. Off-site replication is on the roadmap.

No authenticity check. Mahad OCR reads documents; it does not judge whether a document is genuine, and a verified status does not certify a document as genuine.

Reporting a vulnerability

Email [email protected] with "Security Report" in the subject. Full terms on the Security Policy page.