Trust and security
AhlanHamad holds salaries and personal records, so we treat that data as sensitive from day one. This page lists the protections running in the product today, what we can arrange for your contract, and, just as plainly, what we don't have yet.
In the product today
Signing in
- Email and password, plus a 6-digit code sent to your inbox on every sign-in. A correct password on its own never opens an account.
- A mobile number with a one-time code delivered on WhatsApp, for staff without a company email. They join through an invite from HR.
- Continue with Google or LinkedIn.
- Repeated failed attempts at signing in, signing up, resetting a password or entering a code are rate-limited per account.
- On our side, granting access to our operator console or opening a customer's account for support needs a fresh sign-in, even inside an active session.
- An optional Face ID or fingerprint lock on the employee app. The biometric check happens on the phone and never reaches us.
In the product today
Who sees what
- Eight built-in roles, from CEO, HR and finance through payroll officer and PRO to employee and read-only.
- Custom roles for structures that don't fit the standard eight, with safeguards so nobody can raise their own access.
- Permissions per capability, not all-or-nothing: someone can manage employee records without ever seeing a salary.
- Temporary cover for a colleague on leave, with access that expires on its own on the date you set.
- Every permission is checked again on our servers for every request. Hiding a button is never the only lock.
In the product today
Each company kept apart
- Every company's records are scoped to that company. A request for another company's record is answered "not found", so we don't even confirm that it exists.
- Automated tests that try to reach another company's data run on every change before it ships. If one of them ever succeeds, the release stops.
In the product today
Protecting the data itself
- Every page and every request travels over HTTPS, and browsers are told never to fall back to an unencrypted connection.
- Credentials for systems you connect, such as accounting software, are encrypted separately, with a key that lives only on our servers and never in the browser.
- Our pages can't be framed inside another website, a common trick for capturing clicks.
In the product today
Records and oversight
- An audit log of sensitive actions: who did what, to which record and when. Only the people you give audit access can read it, and it stays within your company.
- Built-in ISO 27001:2022 gap and SOC 2 readiness scorecards that assess the live system from its own data. Controls that can't be evidenced from the system are marked "not assessed" rather than given a pass.
- No change reaches production directly: each one is reviewed and passes an automated verification suite first.
Available on request
Where your data lives
Today AhlanHamad runs on a managed cloud platform. Some features rely on third-party services, such as email delivery and the AI assistant; we will list them for your security review.
- The platform can also run on dedicated infrastructure, including a server in your country or your own datacentre. That is a supported setup rather than a rebuild. We scope it with you and write the timeline into the contract.
Not yet
What we don't have yet
We would rather tell you now than have a security review find it later.
- SOC 2 or ISO 27001 certification. We run the gap assessments above and are working on readiness, but certification needs an external auditor and we do not hold it today.
- An independent penetration test on record.
- Enterprise single sign-on (SAML) and sign-in with a national digital ID. Neither is available today.
- Authenticator-app two-factor codes. We use one-time codes by email or WhatsApp instead.
Security questions
Have a security questionnaire or a hosting requirement? Send it to us and we will answer it line by line.
About AhlanHamad & how we verify figures· Compare all six GCC countries side by side