We run our own storage
Your data is held in HAiCapita-operated PostgreSQL databases and MinIO object storage — not a third-party storage cloud. Data is encrypted in transit (TLS) and at rest.
Trust & Security
HAiCapita is an Egypt-based information-security company. This is an honest look at our actual security posture — with no overstated claims.
Your data is held in HAiCapita-operated PostgreSQL databases and MinIO object storage — not a third-party storage cloud. Data is encrypted in transit (TLS) and at rest.
Every state-changing action is written to a hash-chained, write-once (WORM) audit log. Reordering, deleting or altering a record breaks the chain and is detectable.
The browser never holds a usable token. With phantom-token sessions, it carries only an opaque, unguessable reference — the real access and refresh tokens live in a server-side store and never reach the browser, so a cross-site-scripting payload has nothing to steal. A same-origin token-mediating backend (BFF) resolves that reference, attaches credentials to API calls server-side and refreshes them transparently, and enforces CSRF (same-origin + double-submit) on every state-changing request.
Every state-changing request runs a per-request, default-deny authorization pipeline — verified identity, then a policy decision (OPA/ABAC), then an entitlement gate, then a tamper-evident audit emit. Access is scoped by tenant isolation (database row-level security), a role-by-capability matrix, owner-scoping, and PII/sensitivity gates. Authorization is decided fresh on each call, never trusted from the session alone.
Data and AI operations pass through a sovereignty engine so that the tenant’s jurisdiction drives behaviour — keeping processing aligned with the rules that apply to you.
Our managed service stores data with MENA-region residency, designed for organisations that must keep data in-region.
The same platform ships as a fully air-gapped, on-premises deployment with zero external egress — all data stays inside your own infrastructure, with no external sub-processors.
Identity is managed by Keycloak with role-based access control and enforced multi-factor authentication — every user must enrol a second factor (TOTP authenticator), with phishing-resistant passkeys (WebAuthn / Windows Hello) supported for passwordless sign-in. Network access is fronted and protected by Cloudflare.
Sub-processors
We keep the list deliberately small. Our managed service uses only these two; the air-gapped deployment uses neither.
Certifications
Honestly: we do not currently hold a third-party-certified SOC 2 or ISO certification. Our posture is self-assessed and we are working towards external certification.
Breach notification
If a personal-data breach occurs that is likely to affect you, we commit to notifying the relevant controller — and, where we are the controller, affected individuals and authorities — without undue delay and within the timeframes the applicable law requires.
Read our Privacy Policy and Data Processing Addendum, or contact us for the sub-processor list and security measures.