HaqeebaHaqeeba
Security

Security & compliance by design.

Haqeeba is built for regulated environments. Our security program covers infrastructure, application, data, and operational controls, verified by independent auditors.

Certifications & attestations

SOC 2 Type II

Security, Availability, Confidentiality

Annual independent audit by A-LIGN. Reports available under NDA.

ISO 27001

Information Security Management

Certified by BSI. Covers all cloud and on-prem deployments.

GDPR

Data Protection Compliance

DPA available. EU data residency option. No US government access.

HIPAA Ready

Healthcare Data

BAA available for Enterprise. Encrypted PHI handling controls.

Data protection

Encryption at rest

AES-256 for all persistent data. Customer-managed keys (CMK) available on Enterprise — you hold the root key, we never see it.

  • Database: AES-256-GCM
  • Object storage: SSE-S3 + CMK
  • Backups: Encrypted with separate key

Encryption in transit

TLS 1.3 minimum for all connections. mTLS for ERP connectors. Certificate pinning available.

  • API: TLS 1.3, HSTS
  • ERP: mTLS + client certs
  • Inter-service: mTLS (Istio)

Data residency

Choose your region: US (Virginia), EU (Frankfurt), UK (London), AU (Sydney). Data never leaves the selected region.

  • Primary + DR in same jurisdiction
  • No cross-region replication by default
  • GDPR Schrems II compliant

Data retention & deletion

Configurable retention policies. Cryptographic erasure on demand. 30-day recovery window.

  • Default: 90 days post-contract
  • Custom: 1 day – 7 years
  • Verified destruction certificates

Access control

Authentication

  • SAML 2.0 / OIDC (Okta, Entra ID, Ping, custom)
  • MFA enforced (TOTP, WebAuthn, Duo)
  • SSO session timeout: configurable (default 8hr)
  • API keys: scoped, rotatable, expirable

Authorization (RBAC)

  • Roles: Admin, Analyst, Viewer, Developer
  • Resource-level permissions (per ERP, per model)
  • Custom roles on Enterprise
  • Just-in-time access for support

Audit logging

  • All auth/authz decisions logged
  • Immutable write-once storage
  • SIEM integration (Splunk, Sentinel, Datadog)
  • Real-time alerting on anomalies

Infrastructure security

Cloud provider

AWS (primary) + GCP (DR). All services in dedicated VPCs. No shared tenancy.

Network

Private subnets only. NAT for egress. WAF + DDoS protection. PrivateLink for ERP.

Container security

EKS/GKE. Distroless images. Signed builds (cosign). Runtime security (Falco).

Secrets management

AWS Secrets Manager / HashiCorp Vault. No secrets in code, config, or images.

Vulnerability management

Daily SAST/DAST/SCA. 24hr SLA for critical. Annual pen test (Bishop Fox).

Incident response

24/7 on-call. <4hr detection. Customer notification within 24hr of confirmed breach.

AI safety & governance

Model governance

  • Model cards for every production model
  • Bias & fairness testing per deployment
  • Drift monitoring (statistical + semantic)
  • Human-in-the-loop required for financial actions

Source traceability

  • Every output cites source ERP records
  • Immutable inference logs (7 years)
  • Reproducibility: same input → same output + citations
  • No training on customer data

Red teaming

  • Quarterly adversarial testing
  • Financial hallucination benchmarks
  • Prompt injection & jailbreak testing
  • Public bug bounty (HackerOne)

Report a vulnerability

We take security research seriously. Responsible disclosure via direct email.

Need compliance artifacts?

SOC 2 report, ISO certificate, DPA, BAA, penetration test summary, available under NDA.