Security
Security by design, at every layer of our software.
Ibn Miyeta Group builds and operates institutional-grade SaaS. Security is engineered into every product — from encryption and infrastructure to privacy, compliance and incident response.
01
Encryption
All data is encrypted in transit and at rest. Traffic uses TLS 1.2+. Application secrets are managed by dedicated secret managers, and keys are rotated on a regular cadence.
- —TLS 1.2+ everywhere
- —AES-256 at rest
- —Managed secrets and regular key rotation
- —Encrypted backups
02
Privacy
Personal data is collected minimally, processed lawfully and never sold. Our privacy policy details the categories of data we process, our legal bases and the rights available to data subjects.
- —Data minimization by default
- —Data subject rights honoured on request
- —Regional data residency options on enterprise plans
- —Explicit consent flows
03
Compliance
Our engineering aligns with recognised security standards. We prepare for and pursue independent audits as we scale, with published attestations available to enterprise customers under NDA.
- —GDPR-aligned processing
- —SOC 2-aligned engineering practices
- —DPA available on enterprise plans
- —Vendor risk management
04
Infrastructure
Cloud-native, multi-region infrastructure with infrastructure-as-code, autoscaling and disaster-recovery by design. All production deployments are logged, reversible and covered by monitoring.
- —Infrastructure-as-code
- —Multi-region deployments
- —Autoscaling and DR
- —24/7 monitoring on production systems
05
Responsible Disclosure
We welcome coordinated vulnerability disclosures from the security community. Please email security@ibnmiyetagroup.com — we will acknowledge receipt within two business days and coordinate remediation with you.
06
Incident Response
We maintain an incident response process aligned with industry good practice. In-scope incidents are triaged, communicated to affected customers and post-mortemed transparently.
- —24/7 on-call rotation
- —Clear severity classification
- —Customer notification workflow
- —Public post-mortem for material incidents
07
Data Protection
Data protection is a first-class discipline — from data classification to processor obligations. DPAs are available on request; sub-processors are documented and updated on our Trust Centre.
Report a vulnerability
Coordinated vulnerability disclosure
If you believe you have found a security issue in an Ibn Miyeta Group product or service, please contact us. We will acknowledge receipt and coordinate remediation with you.