Security & Data Protection
Last updated: 2026-09-01 · AWJAN Information Technology Company — Jeddah, Saudi Arabia
Encryption
- In transit: HTTPS/TLS 1.2+ only across all interfaces, with HSTS and forced redirects.
- At rest: Amazon refresh and access tokens are encrypted with AES-256-GCM using a 256-bit key stored outside the database, in a protected configuration file outside the web root.
- Passwords are bcrypt-hashed and never stored in any recoverable form.
- We store no card numbers and no CVV; payments are handled by a PCI-DSS compliant provider (Moyasar) and we retain only a token that is useless outside our provider account.
Access control
- Role-based access: owner, admin, agent, viewer — each with defined permissions; billing is owner-only.
- Strict tenant isolation: every customer row carries the owner user_id and every query is scoped to it.
- Optional two-factor authentication (TOTP) per user and rate limiting on authentication routes.
- Staff access to production data is least-privilege and every administrative access is logged.
Amazon data protection
- We comply with the Amazon Data Protection Policy and use only official APIs.
- Purpose limitation: Amazon data is used solely to deliver the requested service; never shared, sold, or used for another customer.
- We retain no buyer PII; where required it is fetched just-in-time via a Restricted Data Token.
- Deletion within 30 days of authorisation revocation or account closure.
Monitoring and logging
- An audit trail for every sensitive action (account connect/disconnect, permission change, price change, listing publish, billing events).
- Failed-job and error monitoring with admin alerting; logs purged automatically after 60 days.
- Daily encrypted database backups with periodic restore testing.
Incident response
- Roles: Incident Commander (CTO) — Communications Lead — Forensics/Analysis Lead — Amazon Liaison.
- Phases: detection and triage within one hour, containment and revocation of affected tokens, eradication and recovery, then a post-incident report within 5 business days.
- Notification: we notify Amazon at security@amazon.com within 24 hours of discovering any incident affecting Amazon data, and notify affected customers and Saudi regulators as legally required.
- The plan is reviewed and exercised at least every 6 months and updated after every incident.
Secure development
- Prepared statements everywhere — no SQL assembled from user input.
- CSRF protection on all POST requests, output escaping against XSS, and security headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy).
- Change review before deployment and regular security patching of the runtime environment.
التشفير
- التشفير أثناء النقل: HTTPS/TLS 1.2+ حصريًا لكل الواجهات، مع HSTS وإعادة توجيه إجبارية.
- التشفير أثناء التخزين: رموز أمازون (refresh/access tokens) مشفّرة بخوارزمية AES-256-GCM بمفتاح 256-بت يُحفظ خارج قاعدة البيانات في ملف إعداد محمي خارج جذر الويب.
- كلمات المرور مُجزّأة bcrypt، ولا تُخزَّن بأي صورة قابلة للاسترجاع.
- لا نخزّن أرقام البطاقات ولا CVV؛ المدفوعات تُعالج لدى مزوّد متوافق مع PCI-DSS (موياسر) ولا نحتفظ إلا برمز (Token) لا يصلح خارج حسابنا لدى المزوّد.
التحكم في الوصول
- صلاحيات مبنية على الأدوار: مالك، مدير، منفّذ، مشاهد — لكل دور صلاحيات محددة، والفوترة للمالك فقط.
- عزل كامل بين المستأجرين: كل صف في قاعدة البيانات يحمل معرّف المالك (user_id) وكل استعلام مقيّد به.
- تحقق بخطوتين (TOTP) اختياري لكل مستخدم، وتحديد معدل المحاولات على مسارات الدخول.
- وصول الموظفين إلى بيانات الإنتاج مقصور على الحد الأدنى الضروري، ويُسجَّل كل وصول إداري.
حماية بيانات أمازون
- نلتزم بسياسة حماية البيانات الخاصة بأمازون (Amazon Data Protection Policy) ونستخدم الواجهات الرسمية فقط.
- تحديد الغرض: تُستخدم بيانات أمازون حصريًا لتقديم الخدمة المطلوبة، ولا تُشارك ولا تُباع ولا تُستخدم لصالح عميل آخر.
- لا نحتفظ ببيانات التعريف الشخصية للمشترين؛ وعند الحاجة تُستدعى لحظيًا عبر Restricted Data Token.
- الحذف خلال 30 يومًا من سحب التفويض أو إغلاق الحساب.
المراقبة والسجلات
- سجل تدقيق لكل عملية حساسة (ربط/فصل حساب، تغيير صلاحيات، تغيير سعر، نشر قائمة، عمليات الفوترة).
- مراقبة المهام الفاشلة والأخطاء وتنبيه الإدارة، وتنظيف السجلات تلقائيًا بعد 60 يومًا.
- نسخ احتياطية يومية مشفّرة لقاعدة البيانات مع اختبار استرجاع دوري.
الاستجابة للحوادث
- الأدوار: قائد الحادث (المدير التقني) — مسؤول الاتصال — مسؤول الأدلة والتحليل — مسؤول العلاقة مع أمازون.
- المراحل: الاكتشاف والتصنيف خلال ساعة، الاحتواء وإبطال الرموز المتأثرة، الاستئصال والاسترجاع، ثم تقرير ما بعد الحادث خلال 5 أيام عمل.
- الإشعار: نبلغ أمازون على security@amazon.com خلال 24 ساعة من اكتشاف أي حادث يمس بيانات أمازون، ونبلغ العملاء المتأثرين والجهات التنظيمية في المملكة حسب المتطلبات النظامية.
- تُراجَع الخطة وتُختبر كل 6 أشهر على الأقل، وتُحدَّث بعد كل حادث.
دورة التطوير الآمن
- استعلامات مُعدّة (Prepared statements) في كل مكان — لا تركيب SQL نصيًا من مدخلات المستخدم.
- حماية CSRF على كل طلبات POST، وترميز المخرجات لمنع XSS، ورؤوس أمان (X-Frame-Options, X-Content-Type-Options, Referrer-Policy).
- مراجعة التغييرات قبل النشر، وتحديثات أمنية دورية لبيئة التشغيل.
Privacy · Terms · Security · Contact