ModarhemModarhem
Back to Home

Security & Encryption

Last updated: September 15, 2026

Modarhem is built for Saudi businesses handling regulated financial data: ZATCA invoices, payroll, customer records. This page summarises how we protect that data.

1. Encryption at Rest

Your data is stored in an encrypted database. Backups are taken every day, with a copy kept off-site.

2. Encryption in Transit

Every connection to Modarhem is encrypted with TLS, and browsers are instructed to use encrypted connections only (HSTS).

3. Extra Encryption for Sensitive Fields

The most sensitive values, such as two-factor authentication secrets, ZATCA signing keys, integration access tokens, bank IBANs and employee national ID / Iqama numbers, are encrypted individually before they are stored, on top of the database's own encryption.

4. Password Hashing

Passwords are never stored. We keep only a one-way hash made with a modern, memory-hard algorithm, so a stored hash cannot be turned back into the password.

5. Payment Card Data

We never see your customers' card numbers. All subscription payments and (where enabled) customer checkouts are tokenized by Moyasar, a PCI-DSS Level 1 service provider. We store only the last 4 digits and the brand for UI display. No PAN, no CVV, no expiry dates.

6. Multi-Tenancy Isolation

Access to an organization's records is controlled through its membership and permissions, and every request is limited to the organization it was made for.

7. Role-Based Access Control + MFA

Each organization gives its members roles, and owners can adjust what each role and each member may do. Every user can turn on two-factor authentication; once it is on, sensitive actions such as plan changes, cancellation and permission changes ask for a two-factor code before they complete.

8. Session Security

Sign-in sessions expire automatically after a period of inactivity, and signing out ends the session on that device.

9. Audit Trail

Changes to business records, such as issued invoices, recorded payments, invitations and permission changes, are written to an audit trail that cannot be edited, showing who made the change, when, and the values before and after. It is kept for 84 months by default; shortening that window starts a 30-day grace period before anything is deleted.

10. What Is Not Separately Encrypted

Customer and supplier contact details (names, phone numbers, email addresses and billing addresses) are not encrypted individually, because they are searched, filtered and printed on invoices all the time. They are protected by the database's encryption, encrypted connections and your organization's access controls. If you need extra discretion for a particular customer, use a display name and keep their full identity outside the system.

11. Incident Response

If we detect a security incident that affects your data, we will notify you by email within 72 hours of confirmation. If you believe you have found a vulnerability, email security@modarhem.com. We read every report, respond within 2 business days, and credit responsible disclosure.

12. Regulatory Alignment

Modarhem is built to meet Saudi Arabia's Personal Data Protection Law (PDPL: Royal Decree M/19) and ZATCA's Phase 2 e-invoicing requirements. This includes data-subject export (the Export Everything bundle on the Settings page), retention controls and audit trails. Full localization inside the Kingdom is coming soon. Personal-data sharing and international transfers are described in our Privacy Policy.

Questions about our security posture? Email security@modarhem.com. For general privacy inquiries, see our Privacy Policy.