Security & Encryption
Last updated: September 15, 2026
Modarhem is built for Saudi businesses handling regulated financial data: ZATCA invoices, payroll, customer records. This page summarises how we protect that data.
1. Encryption at Rest
Your data is stored in an encrypted database. Backups are taken every day, with a copy kept off-site.
2. Encryption in Transit
Every connection to Modarhem is encrypted with TLS, and browsers are instructed to use encrypted connections only (HSTS).
3. Extra Encryption for Sensitive Fields
The most sensitive values, such as two-factor authentication secrets, ZATCA signing keys, integration access tokens, bank IBANs and employee national ID / Iqama numbers, are encrypted individually before they are stored, on top of the database's own encryption.
4. Password Hashing
Passwords are never stored. We keep only a one-way hash made with a modern, memory-hard algorithm, so a stored hash cannot be turned back into the password.
5. Payment Card Data
We never see your customers' card numbers. All subscription payments and (where enabled) customer checkouts are tokenized by Moyasar, a PCI-DSS Level 1 service provider. We store only the last 4 digits and the brand for UI display. No PAN, no CVV, no expiry dates.
6. Multi-Tenancy Isolation
Access to an organization's records is controlled through its membership and permissions, and every request is limited to the organization it was made for.
7. Role-Based Access Control + MFA
Each organization gives its members roles, and owners can adjust what each role and each member may do. Every user can turn on two-factor authentication; once it is on, sensitive actions such as plan changes, cancellation and permission changes ask for a two-factor code before they complete.
8. Session Security
Sign-in sessions expire automatically after a period of inactivity, and signing out ends the session on that device.
9. Audit Trail
Changes to business records, such as issued invoices, recorded payments, invitations and permission changes, are written to an audit trail that cannot be edited, showing who made the change, when, and the values before and after. It is kept for 84 months by default; shortening that window starts a 30-day grace period before anything is deleted.
10. What Is Not Separately Encrypted
Customer and supplier contact details (names, phone numbers, email addresses and billing addresses) are not encrypted individually, because they are searched, filtered and printed on invoices all the time. They are protected by the database's encryption, encrypted connections and your organization's access controls. If you need extra discretion for a particular customer, use a display name and keep their full identity outside the system.
11. Incident Response
If we detect a security incident that affects your data, we will notify you by email within 72 hours of confirmation. If you believe you have found a vulnerability, email security@modarhem.com. We read every report, respond within 2 business days, and credit responsible disclosure.
12. Regulatory Alignment
Modarhem is built to meet Saudi Arabia's Personal Data Protection Law (PDPL: Royal Decree M/19) and ZATCA's Phase 2 e-invoicing requirements. This includes data-subject export (the Export Everything bundle on the Settings page), retention controls and audit trails. Full localization inside the Kingdom is coming soon. Personal-data sharing and international transfers are described in our Privacy Policy.
Questions about our security posture? Email security@modarhem.com. For general privacy inquiries, see our Privacy Policy.