Skip to content
Security

Your title deeds, bank details and national IDs live here.

That is a higher bar than most business software has to clear, and it is the bar the architecture was designed against — not one it was retrofitted to meet.

Security

Built for the company whose auditor asks hard questions.

Real estate platforms hold title deeds, bank details, salary information and national IDs. That deserves more than a padlock icon on the pricing page.

Encrypted end to end

TLS 1.3 in transit with certificate verification enforced. AES-256 at rest across the database, object storage and backups.

Row-level tenant isolation

Enforced in the database, not the application. The connection role cannot bypass it, so a bug in application code cannot leak across companies.

Role-based access control

Roles, scopes and field-level rules. Permissions are evaluated server-side on every request, never trusted from the client.

Append-only audit trail

Every state change recorded with actor, timestamp, source address and before/after values. Journal lines are immutable once posted.

Backups and recovery

Point-in-time recovery with a 15-minute RPO, automated restore rehearsals and a documented, tested DR runbook.

Compliance programme

GDPR-aligned processing, UAE data residency and DPAs available for enterprise agreements. A SOC 2 Type II programme is under way — AQARI ONE is not yet certified, and we will not say otherwise until the report is issued.

Security documentation, penetration-test summaries and a completed CAIQ are available under NDA during evaluation.

Controls

What your security review will ask about.

Written the way an assessor reads it. A completed CAIQ and our security documentation are available under NDA.

Isolation

  • Row-level security enforced by the database, not application code
  • The application's connection role cannot bypass the policy
  • Tenant scope is set per request and cannot be widened by a query
  • Adversarial isolation tests run in CI against a non-privileged role

Access

  • Role, scope and field-level permissions evaluated server-side
  • Multi-factor authentication with enforced policy per role
  • SAML/OIDC single sign-on and SCIM provisioning
  • Session revocation and forced re-authentication on privilege change

Data

  • TLS 1.3 in transit with certificate verification enforced
  • AES-256 at rest across database, object storage and backups
  • UAE region by default; EU and KSA available
  • Data does not leave the selected region, including for AI inference

Assurance

  • Append-only audit trail with actor, source and before/after values
  • Point-in-time recovery with a 15-minute RPO
  • Restore rehearsals on a schedule, with a documented DR runbook
  • Independent penetration testing; summaries available under NDA
Start here

See it running on your own portfolio.

A 45-minute session with an engineer who knows the domain, not a slide deck. Bring a real lease, a real invoice and your hardest question.

No sales sequence. One engineer, 45 minutes, your data model on screen.