This page summarizes Bedaki's security posture for customers, sub-processors, and partners (including Meta) evaluating us. For a full security questionnaire, audit reports, or our Information Security Management System (ISMS) documentation, contact security@bedaki.com.
Encryption
- In transit: TLS 1.2+ on all customer-facing and internal endpoints. HSTS enforced on the public website.
- At rest: AES-256 for the primary database, object storage, and backup volumes.
- Secrets: managed via a dedicated secret store, never committed to source control or container images.
Access Control
- Role-based access control (RBAC) with permissions scoped per tenant; deny-by-default.
- Two-factor authentication available for all customer accounts and required for all Bedaki employees with production access.
- JWT-based session management with short-lived tokens and token-version invalidation on permission change.
- All production access is logged in an immutable audit trail (Bedaki Activity History) and reviewed quarterly.
Infrastructure
- Multi-tenant architecture with strict row-level account isolation enforced at the database layer.
- Redis-backed session store with TTL-bounded entries; no long-lived sensitive payloads in cache.
- Containerized services with image scanning before deployment; dependency vulnerability checks on every build.
- Backups encrypted, geographically separated, and tested for restoration on a rolling 30-day schedule.
Incident Response
- Documented incident-response runbook with defined severity levels and on-call rotation.
- We commit to notifying affected customers within 72 hours of confirming a personal-data breach, and the CNDP and Meta (where Platform Data is involved) within the same window.
- Post-incident: root-cause analysis published to affected customers and fix tracked in the public security log.
Application Security
- Static code analysis on every pull request.
- Pre-merge code review by a second engineer; no direct pushes to protected branches.
- Annual third-party penetration test (results available under NDA).
- Annual SOC 2-style readiness review; we will pursue formal certification once we cross the customer-data-volume threshold that justifies the audit cadence.
Compliance Posture
- Moroccan Law 09-08 (data protection), declared with CNDP
- GDPR alignment for EEA customers and end users (via SCCs and DPA on request)
- Meta Platform Terms and WhatsApp Business Solution Terms (BSP requirements)
- PCI DSS scope limited, card payments are tokenized and processed by Vantage Payment Systems SA (Payzone), a Bank Al-Maghrib licensed payment institution; Bedaki never stores, transmits, or processes raw cardholder data (PAN, expiry, CVV/CVC)
Report a Vulnerability
Email security@bedaki.com. We acknowledge within 48 hours and aim to triage within 5 business days. A formal bug-bounty program is in planning. security@bedaki.com