Security Overview
Enterprise-grade encryption, immutable transaction ledgers, and zero-trust architecture protecting every interaction.
1. Security as an Architectural Foundation
Security at Wamaaz is engineered directly into our technological foundation. From proprietary double-entry cryptographic financial ledgers to strict role-based access control (RBAC), we ensure that your account, payment credentials, and transaction histories remain impenetrable.
2. Data Encryption in Transit & At Rest
- Transit Encryption: All incoming and outgoing connections enforce TLS 1.3 with forward secrecy and HSTS (HTTP Strict Transport Security) headers.
- Rest Encryption: Customer records and sensitive attributes in our PostgreSQL database are encrypted utilizing AES-256 with key rotation managed via hardware security modules.
3. Level 1 PCI-DSS Payment Certification
Payment transactions are tokenized via globally certified Level 1 PCI-DSS financial partners (Stripe, PayPal, Wise, Apple Pay). Sensitive primary account numbers (PAN) never touch Wamaaz internal application servers, eliminating attack surfaces.
4. Passkeys, Multi-Factor Auth & Session Hygiene
Wamaaz supports modern biometric authentication (Passkeys / WebAuthn) alongside time-based one-time password (TOTP) protocols. Sessions are protected with cryptographically signed cookies and automatic timeouts.
Questions regarding this document?
Our concierge team is available 8am–12am ET. Call +44 (784) 3906270 or message us.