Security Policy

Last updated 2026-08-02

How ValiCrew protects the data you put in it. To report a security issue, see Vulnerability Disclosure.

Where it runs

Oracle Cloud Infrastructure in Abu Dhabi, United Arab Emirates. Application, database, object storage and backups all sit in the UAE.

Isolation between customers

Each workspace has its own database schema, not a shared table with a tenant column. A query that forgets to filter by customer returns nothing rather than someone else's records — the isolation is structural rather than something every query has to remember.

Within a workspace, records are further scoped by company for organisations that run more than one.

Encryption

In transit: HTTPS everywhere, with modern TLS.

At rest: the database and backups are encrypted. On top of that, the fields that would matter most if anything were ever exposed are individually encrypted before they are stored — Emirates ID and passport numbers, salary figures and components, bank IBANs, and the credentials for connected storage. Each workspace has its own encryption key, so keys cannot be reused across customers.

Passwords are hashed, never stored in a form that can be reversed.

Access control

Role-based permissions with least privilege. Sessions expire on inactivity, and a change to a user's security state invalidates their existing sessions.

Our own staff access is limited to what is needed to operate and support the service, and is logged.

Audit logging

Changes to records are recorded with who, what and when. Sensitive values are excluded from the log itself — the audit trail shows that a salary changed, not what it changed to.

Security-relevant events (sign-in failures, permission changes, document access, payroll locking) are logged and monitored.

Uploaded files

Every upload passes the same pipeline: type validation, a check of the actual file bytes rather than the filename, and a malware scan. A file that fails the scan is quarantined on platform storage for review — never written to your connected cloud — and the event is recorded.

Where you have connected SharePoint or Google Drive, files land in your storage. See Customer Data & Storage.

Backups

Automated daily backups, encrypted, of the database and object storage. Restores are tested on a schedule, because a backup that has never been restored is not a backup.

Payments

We do not store card details. Payment data goes directly to Stripe, a PCI-DSS Level 1 provider.

Vulnerability management

Dependencies are scanned for known vulnerabilities on every change through our CI pipeline, and patched on a timeline set by severity. An independent penetration test is planned annually.

Incident response

We maintain a documented process — detect, contain, eradicate, recover, review — and a breach register. If an incident affects your data, we will tell you without undue delay and give you what you need for your own notification obligations under PDPL Article 9.

What we are not claiming

We are not currently SOC 2 certified. The platform has been built against SOC 2 Trust Services Criteria and the controls above map to them, but an audit has not yet been completed and we will not imply otherwise. We would rather tell you where we actually are.

Contact

[email protected]

Lenouar Artificial Intelligence Developing Services LLC · Al Muroor, Abu Dhabi, United Arab Emirates · Commercial registration CN-6272765

All site policies