Security
How your documents are protected
This page describes what is actually implemented. Where something is not in place, it says so.
In place today
Tenant isolation
Every document, key and result is scoped to one tenant. Cross-tenant reads are structurally prevented and covered by automated tests.
API key handling
Keys are generated server-side, shown once, and stored only as SHA-256 hashes. A key can be disabled instantly.
Password security
Passwords are bcrypt-hashed. Repeated failed logins lock the account temporarily.
Email and phone verification gate
Accounts cannot sign in until the email address is verified, and scanning and API keys open only after the phone number is verified too.
WhatsApp two-factor
Accounts with a verified phone receive a WhatsApp one-time code at sign-in.
Hash-chained audit log
Significant actions are appended to a chained log, making silent changes detectable.
Database backups
A database backup is taken automatically before every deployment, before any migration runs.
Platform access control
Internal business dashboards are restricted to named Mahad staff accounts — a customer account can never reach them.
What we do not claim
No third-party certification. We hold no ISO 27001, SOC 2 or equivalent audit, and we do not claim certified GDPR compliance.
No uptime SLA. No contractual availability guarantee is offered today.
Off-site backup is not yet enabled. Backups are stored on the same infrastructure as the service. Off-site replication is on the roadmap.
No authenticity check. Mahad OCR reads documents; it does not judge whether a document is genuine, and a verified status does not certify a document as genuine.
Reporting a vulnerability
Email [email protected] with "Security Report" in the subject. Full terms on the Security Policy page.