Security

Security by design, at every layer of our software.

Ibn Miyeta Group builds and operates institutional-grade SaaS. Security is engineered into every product — from encryption and infrastructure to privacy, compliance and incident response.

01

Encryption

All data is encrypted in transit and at rest. Traffic uses TLS 1.2+. Application secrets are managed by dedicated secret managers, and keys are rotated on a regular cadence.

  • TLS 1.2+ everywhere
  • AES-256 at rest
  • Managed secrets and regular key rotation
  • Encrypted backups

02

Privacy

Personal data is collected minimally, processed lawfully and never sold. Our privacy policy details the categories of data we process, our legal bases and the rights available to data subjects.

  • Data minimization by default
  • Data subject rights honoured on request
  • Regional data residency options on enterprise plans
  • Explicit consent flows

03

Compliance

Our engineering aligns with recognised security standards. We prepare for and pursue independent audits as we scale, with published attestations available to enterprise customers under NDA.

  • GDPR-aligned processing
  • SOC 2-aligned engineering practices
  • DPA available on enterprise plans
  • Vendor risk management

04

Infrastructure

Cloud-native, multi-region infrastructure with infrastructure-as-code, autoscaling and disaster-recovery by design. All production deployments are logged, reversible and covered by monitoring.

  • Infrastructure-as-code
  • Multi-region deployments
  • Autoscaling and DR
  • 24/7 monitoring on production systems

05

Responsible Disclosure

We welcome coordinated vulnerability disclosures from the security community. Please email security@ibnmiyetagroup.com — we will acknowledge receipt within two business days and coordinate remediation with you.

06

Incident Response

We maintain an incident response process aligned with industry good practice. In-scope incidents are triaged, communicated to affected customers and post-mortemed transparently.

  • 24/7 on-call rotation
  • Clear severity classification
  • Customer notification workflow
  • Public post-mortem for material incidents

07

Data Protection

Data protection is a first-class discipline — from data classification to processor obligations. DPAs are available on request; sub-processors are documented and updated on our Trust Centre.

Report a vulnerability

Coordinated vulnerability disclosure

If you believe you have found a security issue in an Ibn Miyeta Group product or service, please contact us. We will acknowledge receipt and coordinate remediation with you.