🔒 Security

Security

App-ening takes data security seriously. We comply with UAE Federal Data Protection Law (PDPL).

🔐

Encryption

TLS 1.3 in transit, AES-256 at rest. PII fields encrypted with per-tenant keys.

Compliance

GDPR compliant. UAE Federal Data Protection Law (PDPL) adherent. SOC 2 Type II in progress.

🛡

Infrastructure

Hosted on AWS with automatic backups, monitoring, and incident response.

Infrastructure Security

All data is processed on Amazon Web Services (AWS) infrastructure with enterprise-grade physical and network security.

AWS VPC

Services run inside a Virtual Private Cloud with strict firewall rules and network isolation

DDoS Protection

AWS Shield Standard protects against common network and transport layer attacks

Automated Backups

Point-in-time database recovery. Backups encrypted and stored in separate availability zone

Health Monitoring

Real-time monitoring with Sentry error tracking and automated service restart on failure

Data Encryption

Multiple layers of encryption protect your data at every stage.

Data in Transit

All API calls encrypted with TLS 1.3. HSTS enforced. Secure WebSocket for real-time updates

Data at Rest

AES-256 encryption for all stored data. Database and file storage both encrypted

PII Protection

Phone numbers and personal data encrypted with per-tenant keys. Separate encryption layer above database encryption

WhatsApp E2E

Messages use WhatsApp’s end-to-end encryption via the official Business API

Application Security

Security is built into our development process, not bolted on after.

Secure SDLC

Code reviews, static analysis, and automated security scanning on every deployment

Vulnerability Scanning

Weekly OWASP ZAP and Snyk scans. Dependency audits for known CVEs

Access Control

Role-based access, 2FA, JWT authentication with token rotation. Google SSO supported

API Security

Rate limiting, API key rotation, per-tenant isolation, and request validation on all endpoints

Compliance & Certifications

We maintain compliance with international and local data protection standards.

🌐
GDPR

Full compliance with EU General Data Protection Regulation. Data portability, deletion rights, and consent management.

🔒
UAE Federal Data Protection Law (PDPL)

Adherent to local data protection requirements in UAE. Regular compliance reviews.

WhatsApp Business API

Official WhatsApp Business API via authorised BSP (Gupshup). Meta compliance requirements met.

💳
PCI-DSS

Payment processing via PCI-DSS compliant gateways. We never store card numbers or bank details.

📊
SOC 2 Type II

SOC 2 Type II certification in progress. Security, availability, and confidentiality controls audited.

👤
Multi-Tenant Isolation

Strict logical separation between accounts. Each tenant’s data is isolated with enforced account boundaries.

Data Privacy

We follow data minimisation principles and give you full control over your data.

Data Minimisation

We only collect data necessary to provide our services. No unnecessary tracking or data harvesting.

Audit Logging

Complete audit trail of data access. Know who accessed what and when.

Data Portability

Export your contacts, conversations, and analytics in standard formats (CSV, JSON) at any time.

Right to Deletion

Request complete account deletion. Personal data removed within 30 days. Backups purged within 90 days.

Incident Response

We have documented procedures for detecting, containing, and resolving security incidents.

🔍
Detection

Real-time monitoring via Sentry + automated health checks every 5 minutes

🛑
Containment

Automated service isolation and failover. Slack alerts to engineering team

🔧
Resolution

Root cause analysis, patch deployment, and post-incident review

📣
Notification

Affected customers notified within 72 hours as required by GDPR

User Security Best Practices

We recommend these practices to keep your account secure.

🔑
Use Strong Passwords

At least 12 characters with a mix of letters, numbers, and symbols

📱
Enable Two-Factor Auth

Add an extra layer of security with TOTP-based 2FA

🗝
Rotate API Keys

Regularly rotate API keys and revoke any that are no longer in use

👁
Monitor Activity

Check login history and active sessions regularly in your settings

Report a Security Issue

Found a vulnerability? We appreciate responsible disclosure. We acknowledge all reports within 24 hours.

security@app-ening.comprivacy@app-ening.com

For data requests under UAE Federal Data Protection Law (PDPL), contact privacy@app-ening.com.