Security Overview

Infinite Barakah Ventures · Cashflow OS · 10 August 2026

Tenant isolation

Every table holding customer data carries an org_id and is protected by PostgreSQL row-level security. Isolation is enforced by a restrictive policy in the database, evaluated against the signed-in user's session — not by application code that could be bypassed by a missing filter. Write permission is evaluated per organization, so a user who administers one organization holds no elevated rights in another.

Authentication and access control

Encryption

All traffic is TLS 1.2 or higher. Data at rest is encrypted with AES-256 by the managed platform. Third-party credentials, such as Zoho refresh tokens, are stored service-side and are never sent to the browser.

Audit trail

Every create, update and delete on customer data writes an append-only audit record holding the table, row, before and after values, actor and timestamp. Per-row history is visible in the application; the log itself is not editable through it.

Hosting and backups

Application: Vercel. Database, authentication and storage: Supabase, hosted in AWS ap-southeast-2 (Sydney, Australia), via Supabase. The UAE PDPL does not require data localisation, and no transfer restriction applies to this arrangement; the region is disclosed so customers can assess it.

Automated daily backups are taken of the production database.

Payments

Subscription billing is handled by Stripe. Card data never touches our systems, so we are not in scope for PCI DSS beyond SAQ-A.

Data portability and deletion

Administrators can export the whole organization to Excel at any time, without contacting support. On account closure, data is deleted within 90 days.

Incident response

Suspected incidents are triaged on discovery. Where a breach is likely to prejudice the privacy, confidentiality or security of data subjects, we notify the UAE Data Office and affected customers within 72 hours, per the UAE PDPL.

Certifications

We are not yet SOC 2 certified. A SOC 2 Type I engagement is planned, followed by Type II after the evidence period. We answer security questionnaires directly in the meantime.

Contact

Security questions and vulnerability reports: privacy@infinitebarakah.com.