Trust · Security
Security, in its real state
Controls that are in place today, stated as they are, with no promises attached.
Every control below is true of the version published today.
The list is written for the security questionnaire a company sends a software provider before sharing data with it: where the data is, who can reach it, how long it is kept, and how we take a vulnerability report.
Last updated: 24 September 2026
Controls
- Encryption in transitLive today
All traffic between your browser and the site is encrypted, and any unencrypted request is redirected to the encrypted one.
- Browser controlsLive today
Pages are served with controls that stop the site being embedded in another site, restrict what can load inside a page, and let no form submit anywhere but this site.
- Data minimisationLive today
Forms accept the declared fields and nothing else. We never ask for bank account numbers, card numbers or identity documents.
- Account protectionLive today
Passwords and session tokens are not stored as they are, so a copy of the tables opens no account.
- Automated submission defenceLive today
A request limit on every form, and a check that the sender is a person rather than a script.
- Secret isolationLive today
Service keys stay on the server, and none of them reaches the browser.
- Data residencyLive today
The databases are in Saudi Arabia, and their backups are in the Kingdom with them.
- Access to dataLive today
Access is limited to the people who need it for their work.
- Retention enforcementLive today
Conversations with the site assistant are deleted 180 days after the last message. The deletion runs daily.
Where the data sits
Everything you send through this site is held in databases inside Saudi Arabia, and their backups are in the Kingdom with them.
Your data is not moved outside the Kingdom in the running of this site.
What we do not claim
- We hold no ISO 27001 certificate and no SOC 2 report.
- No independent security audit and no penetration test has been carried out as at the date of this page.
- When a certificate exists, it will be named here with the body that issued it, the date and the scope.
Reporting a vulnerability
If you find a vulnerability, write to us before publishing it, at info@fkahtech.com.
We acknowledge receipt within two working days. We take no action against good-faith security research as long as it avoids other people’s data and does not disrupt the service.