Security & trust
We describe only controls that are implemented. Deployment-dependent items are labelled as such.
Implemented in the product
✓ Tenant isolation on every business query, derived from the authenticated identity.
✓ Access tokens in memory only; rotating HttpOnly refresh cookies with CSRF double-submit.
✓ Role-based access control, full audit trail, and MFA.
✓ Field-level encryption of sensitive data (IBAN, MFA secrets) at rest.
✓ Uploads are content-sniffed and fail closed when the malware scanner is unavailable.
Depends on your deployment
○ TLS/HSTS termination, WAF, and network isolation at the hosting layer.
○ Managed database encryption, backups, and point-in-time recovery.
Honest status
MASAR is a controlled-pilot candidate, not a paid-production service yet. We hold a SOC 2 readiness pack — not a completed audit — and we do not claim any compliance certification. An external penetration test and a KSA payroll legal review are scheduled before paid production.