Security at Bedaki

Last updated: May 2026

This page summarizes Bedaki's security posture for customers, sub-processors, and partners (including Meta) evaluating us. For a full security questionnaire, audit reports, or our Information Security Management System (ISMS) documentation, contact security@bedaki.com.

Encryption

  • In transit: TLS 1.2+ on all customer-facing and internal endpoints. HSTS enforced on the public website.
  • At rest: AES-256 for the primary database, object storage, and backup volumes.
  • Secrets: managed via a dedicated secret store, never committed to source control or container images.

Access Control

  • Role-based access control (RBAC) with permissions scoped per tenant; deny-by-default.
  • Two-factor authentication available for all customer accounts and required for all Bedaki employees with production access.
  • JWT-based session management with short-lived tokens and token-version invalidation on permission change.
  • All production access is logged in an immutable audit trail (Bedaki Activity History) and reviewed quarterly.

Infrastructure

  • Multi-tenant architecture with strict row-level account isolation enforced at the database layer.
  • Redis-backed session store with TTL-bounded entries; no long-lived sensitive payloads in cache.
  • Containerized services with image scanning before deployment; dependency vulnerability checks on every build.
  • Backups encrypted, geographically separated, and tested for restoration on a rolling 30-day schedule.

Incident Response

  • Documented incident-response runbook with defined severity levels and on-call rotation.
  • We commit to notifying affected customers within 72 hours of confirming a personal-data breach, and the CNDP and Meta (where Platform Data is involved) within the same window.
  • Post-incident: root-cause analysis published to affected customers and fix tracked in the public security log.

Application Security

  • Static code analysis on every pull request.
  • Pre-merge code review by a second engineer; no direct pushes to protected branches.
  • Annual third-party penetration test (results available under NDA).
  • Annual SOC 2-style readiness review; we will pursue formal certification once we cross the customer-data-volume threshold that justifies the audit cadence.

Compliance Posture

  • Moroccan Law 09-08 (data protection), declared with CNDP
  • GDPR alignment for EEA customers and end users (via SCCs and DPA on request)
  • Meta Platform Terms and WhatsApp Business Solution Terms (BSP requirements)
  • PCI DSS scope limited, card payments are tokenized and processed by Vantage Payment Systems SA (Payzone), a Bank Al-Maghrib licensed payment institution; Bedaki never stores, transmits, or processes raw cardholder data (PAN, expiry, CVV/CVC)

Report a Vulnerability

Email security@bedaki.com. We acknowledge within 48 hours and aim to triage within 5 business days. A formal bug-bounty program is in planning. security@bedaki.com