Security & Compliance
How Alonah protects business and customer data. This page states only what's actually true of the platform today — no unverified certifications.
01. Data residency
Tenant data is hosted with GCC data residency (AWS Bahrain), aligned with UAE TDRA and Saudi NDMO expectations.
02. Encryption
Data in transit is encrypted (HTTPS/TLS). WhatsApp/BSP API credentials and other sensitive integration secrets are encrypted at rest and never re-displayed once saved.
03. Access control
Role-based access throughout: platform admins vs. limited sub-admins (scoped to specific sections), and per-tenant owner/manager/agent roles. Two-factor authentication is available on login. Admin sessions expire after a defined period and require re-authentication.
04. Audit logging
Sensitive admin actions — including reads of customer/conversation data, not just changes — are recorded in an audit log reviewable by full admins.
05. Payments
Card payments are processed by Stripe, a PCI-DSS Level 1 certified payment processor — Alonah never stores full card numbers.
06. Compliance status
Alonah is not currently certified under SOC 2, ISO 27001, HIPAA, or similar formal frameworks. [PLACEHOLDER] — if a specific certification is a real business goal, that's a scoped compliance project, not a claim to make on this page ahead of an actual audit.
07. Reporting a security issue
If you've found a security issue, contact info@cipherslab.com. [PLACEHOLDER] — a dedicated security@ address is recommended once there's a process to monitor it.