Last updated: February 2026

Security & Compliance

How we protect your data and ensure regulatory compliance across our platform.

Platform Security

Enterprise-grade protections built into every layer of Hisbuu.

Encryption in Transit

All data transmitted between your browser and our servers is encrypted using HTTPS with TLS 1.2+ protocols. API communications are secured with token-based authentication.

Secure Data Storage

Uploaded documents and sensitive files are stored outside the public web directory. CDN-hosted files use signed URLs with expiration controls. Database credentials are never exposed in client-side code.

Authentication & Access
  • Secure session management with auto-expiry
  • CSRF protection on all form submissions
  • Role-based access (Super Admin, Admin, Finance, Supervisor, Driver)
  • Separate admin and driver authentication portals
Application Security
  • Parameterized queries preventing SQL injection
  • Input validation and output encoding against XSS
  • File upload validation (type, size, content verification)
  • Rate limiting on authentication endpoints
Backup & Recovery
  • Automated daily database backups
  • 30-day backup retention
  • Point-in-time recovery capability
  • Geographically separated backup storage
Infrastructure
  • NVMe SSD storage for performance and reliability
  • Bunny CDN for global, low-latency document delivery
  • 99.9% uptime target with monitoring and alerting
  • Self-hosted option available for Enterprise plans

Compliance

Designed to meet regulatory and operational requirements in the GCC.

Multi-Tenant Data Isolation

Each organization's data is logically isolated at the application level. Admins and drivers from one tenant cannot access, view, or modify data belonging to another organization — even on shared infrastructure.

Audit Trails

Complete audit trail for all critical operations — submission approvals, payout processing, document verification, and status changes. Every action is timestamped and linked to the user who performed it.

KYC Document Management

Structured document collection with expiry tracking for Civil IDs, driving licenses, and vehicle registrations. Automated reminders for expiring documents ensure ongoing compliance with local regulations.

Data Residency

For organizations requiring data to remain within specific jurisdictions, our Enterprise and self-hosted plans support on-premise deployment — giving you full control over where your data lives.

Access Controls

Granular role-based permissions ensure each team member only accesses what they need. Finance admins see payouts, supervisors see submissions, drivers see only their own data. Principle of least privilege enforced.

Data Portability

Export your data at any time in standard formats (CSV, Excel). Upon contract termination, we provide a full data export within 30 days and permanently delete your data from our systems thereafter.

HTTPS / TLS Encrypted CSRF Protected Daily Backups Role-Based Access Audit Trails Data Export