SECURITY

Security is a set of enforced boundaries.

Review the security questions Balaawi uses to scope identity, authorization, tenant isolation, data handling, audit evidence, and deployment.

Security claims should be tied to implemented controls and tested evidence. Balaawi scopes access, ownership, sensitive data, operations, and deployment responsibilities before rollout.

Identity and authorization

Authentication establishes identity; server-side authorization decides whether that identity may perform an action in the current context.

  • Use least-privilege roles
  • Protect privileged changes
  • Do not rely on hidden interface controls

Tenant and data boundaries

Tenant context must remain enforced in queries, files, jobs, caches, events, and reports, not merely selected in the browser.

  • Validate context server-side
  • Test cross-tenant denial
  • Preserve ownership on background work

Operational evidence

Backups, logging, monitoring, patching, incident response, and release verification need explicit owners and retained evidence.

  • Define recovery objectives
  • Protect and review audit records
  • Verify production releases
Frequently asked questions

Does this page certify compliance?

No. It describes control areas and scoping questions; any compliance assessment requires defined scope and independent evidence.

Can security requirements be reviewed before purchase?

Yes. Material requirements should be raised during discovery and resolved in written scope before commitment.

Turn the questions into a reviewable scope.

Share the actual operating context. Balaawi starts with discovery; the request form creates neither a workspace nor a charge.

Request discovery