Skip to content
Security

Security & trust

We describe only controls that are implemented. Deployment-dependent items are labelled as such.

Implemented in the product

Tenant isolation on every business query, derived from the authenticated identity.
Access tokens in memory only; rotating HttpOnly refresh cookies with CSRF double-submit.
Role-based access control, full audit trail, and MFA.
Field-level encryption of sensitive data (IBAN, MFA secrets) at rest.
Uploads are content-sniffed and fail closed when the malware scanner is unavailable.

Depends on your deployment

TLS/HSTS termination, WAF, and network isolation at the hosting layer.
Managed database encryption, backups, and point-in-time recovery.
Honest status

MASAR is a controlled-pilot candidate, not a paid-production service yet. We hold a SOC 2 readiness pack — not a completed audit — and we do not claim any compliance certification. An external penetration test and a KSA payroll legal review are scheduled before paid production.