Security & Data Protection

Last updated: 2026-09-01 · AWJAN Information Technology Company — Jeddah, Saudi Arabia

Encryption

  • In transit: HTTPS/TLS 1.2+ only across all interfaces, with HSTS and forced redirects.
  • At rest: Amazon refresh and access tokens are encrypted with AES-256-GCM using a 256-bit key stored outside the database, in a protected configuration file outside the web root.
  • Passwords are bcrypt-hashed and never stored in any recoverable form.
  • We store no card numbers and no CVV; payments are handled by a PCI-DSS compliant provider (Moyasar) and we retain only a token that is useless outside our provider account.

Access control

  • Role-based access: owner, admin, agent, viewer — each with defined permissions; billing is owner-only.
  • Strict tenant isolation: every customer row carries the owner user_id and every query is scoped to it.
  • Optional two-factor authentication (TOTP) per user and rate limiting on authentication routes.
  • Staff access to production data is least-privilege and every administrative access is logged.

Amazon data protection

  • We comply with the Amazon Data Protection Policy and use only official APIs.
  • Purpose limitation: Amazon data is used solely to deliver the requested service; never shared, sold, or used for another customer.
  • We retain no buyer PII; where required it is fetched just-in-time via a Restricted Data Token.
  • Deletion within 30 days of authorisation revocation or account closure.

Monitoring and logging

  • An audit trail for every sensitive action (account connect/disconnect, permission change, price change, listing publish, billing events).
  • Failed-job and error monitoring with admin alerting; logs purged automatically after 60 days.
  • Daily encrypted database backups with periodic restore testing.

Incident response

  • Roles: Incident Commander (CTO) — Communications Lead — Forensics/Analysis Lead — Amazon Liaison.
  • Phases: detection and triage within one hour, containment and revocation of affected tokens, eradication and recovery, then a post-incident report within 5 business days.
  • Notification: we notify Amazon at security@amazon.com within 24 hours of discovering any incident affecting Amazon data, and notify affected customers and Saudi regulators as legally required.
  • The plan is reviewed and exercised at least every 6 months and updated after every incident.

Secure development

  • Prepared statements everywhere — no SQL assembled from user input.
  • CSRF protection on all POST requests, output escaping against XSS, and security headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy).
  • Change review before deployment and regular security patching of the runtime environment.

التشفير

  • التشفير أثناء النقل: HTTPS/TLS 1.2+ حصريًا لكل الواجهات، مع HSTS وإعادة توجيه إجبارية.
  • التشفير أثناء التخزين: رموز أمازون (refresh/access tokens) مشفّرة بخوارزمية AES-256-GCM بمفتاح 256-بت يُحفظ خارج قاعدة البيانات في ملف إعداد محمي خارج جذر الويب.
  • كلمات المرور مُجزّأة bcrypt، ولا تُخزَّن بأي صورة قابلة للاسترجاع.
  • لا نخزّن أرقام البطاقات ولا CVV؛ المدفوعات تُعالج لدى مزوّد متوافق مع PCI-DSS (موياسر) ولا نحتفظ إلا برمز (Token) لا يصلح خارج حسابنا لدى المزوّد.

التحكم في الوصول

  • صلاحيات مبنية على الأدوار: مالك، مدير، منفّذ، مشاهد — لكل دور صلاحيات محددة، والفوترة للمالك فقط.
  • عزل كامل بين المستأجرين: كل صف في قاعدة البيانات يحمل معرّف المالك (user_id) وكل استعلام مقيّد به.
  • تحقق بخطوتين (TOTP) اختياري لكل مستخدم، وتحديد معدل المحاولات على مسارات الدخول.
  • وصول الموظفين إلى بيانات الإنتاج مقصور على الحد الأدنى الضروري، ويُسجَّل كل وصول إداري.

حماية بيانات أمازون

  • نلتزم بسياسة حماية البيانات الخاصة بأمازون (Amazon Data Protection Policy) ونستخدم الواجهات الرسمية فقط.
  • تحديد الغرض: تُستخدم بيانات أمازون حصريًا لتقديم الخدمة المطلوبة، ولا تُشارك ولا تُباع ولا تُستخدم لصالح عميل آخر.
  • لا نحتفظ ببيانات التعريف الشخصية للمشترين؛ وعند الحاجة تُستدعى لحظيًا عبر Restricted Data Token.
  • الحذف خلال 30 يومًا من سحب التفويض أو إغلاق الحساب.

المراقبة والسجلات

  • سجل تدقيق لكل عملية حساسة (ربط/فصل حساب، تغيير صلاحيات، تغيير سعر، نشر قائمة، عمليات الفوترة).
  • مراقبة المهام الفاشلة والأخطاء وتنبيه الإدارة، وتنظيف السجلات تلقائيًا بعد 60 يومًا.
  • نسخ احتياطية يومية مشفّرة لقاعدة البيانات مع اختبار استرجاع دوري.

الاستجابة للحوادث

  • الأدوار: قائد الحادث (المدير التقني) — مسؤول الاتصال — مسؤول الأدلة والتحليل — مسؤول العلاقة مع أمازون.
  • المراحل: الاكتشاف والتصنيف خلال ساعة، الاحتواء وإبطال الرموز المتأثرة، الاستئصال والاسترجاع، ثم تقرير ما بعد الحادث خلال 5 أيام عمل.
  • الإشعار: نبلغ أمازون على security@amazon.com خلال 24 ساعة من اكتشاف أي حادث يمس بيانات أمازون، ونبلغ العملاء المتأثرين والجهات التنظيمية في المملكة حسب المتطلبات النظامية.
  • تُراجَع الخطة وتُختبر كل 6 أشهر على الأقل، وتُحدَّث بعد كل حادث.

دورة التطوير الآمن

  • استعلامات مُعدّة (Prepared statements) في كل مكان — لا تركيب SQL نصيًا من مدخلات المستخدم.
  • حماية CSRF على كل طلبات POST، وترميز المخرجات لمنع XSS، ورؤوس أمان (X-Frame-Options, X-Content-Type-Options, Referrer-Policy).
  • مراجعة التغييرات قبل النشر، وتحديثات أمنية دورية لبيئة التشغيل.

Privacy · Terms · Security · Contact