Security, Availability, Confidentiality
Annual independent audit by A-LIGN. Reports available under NDA.
Haqeeba is built for regulated environments. Our security program covers infrastructure, application, data, and operational controls, verified by independent auditors.
Annual independent audit by A-LIGN. Reports available under NDA.
Certified by BSI. Covers all cloud and on-prem deployments.
DPA available. EU data residency option. No US government access.
BAA available for Enterprise. Encrypted PHI handling controls.
AES-256 for all persistent data. Customer-managed keys (CMK) available on Enterprise — you hold the root key, we never see it.
TLS 1.3 minimum for all connections. mTLS for ERP connectors. Certificate pinning available.
Choose your region: US (Virginia), EU (Frankfurt), UK (London), AU (Sydney). Data never leaves the selected region.
Configurable retention policies. Cryptographic erasure on demand. 30-day recovery window.
AWS (primary) + GCP (DR). All services in dedicated VPCs. No shared tenancy.
Private subnets only. NAT for egress. WAF + DDoS protection. PrivateLink for ERP.
EKS/GKE. Distroless images. Signed builds (cosign). Runtime security (Falco).
AWS Secrets Manager / HashiCorp Vault. No secrets in code, config, or images.
Daily SAST/DAST/SCA. 24hr SLA for critical. Annual pen test (Bishop Fox).
24/7 on-call. <4hr detection. Customer notification within 24hr of confirmed breach.
We take security research seriously. Responsible disclosure via direct email.
SOC 2 report, ISO certificate, DPA, BAA, penetration test summary, available under NDA.