Access isolation
Database row-level rules separate accounts and restrict private records to authorised roles.
الأمان في Studio ATS
يتعامل Studio مع البيانات التجارية وطلبات العملاء وأحداث الدفع. صُممت الصلاحيات والعمليات بحيث يرى كل شخص ما يحتاجه فقط وتبقى الإجراءات الحساسة قابلة للتتبع.
منهجنا
No single control is presented as infallible. Isolation, server-side checks, restricted secrets, signed events and audit trails work together to reduce risk.
Database row-level rules separate accounts and restrict private records to authorised roles.
Short-lived, single-use login codes are stored as keyed hashes rather than usable codes.
Privileged credentials remain server-side and are used only by narrowly scoped services.
Sensitive financial and administrative changes create records that can be investigated.
حماية البيانات
Commercial information is separated by account and purpose. Public forms do not turn private customer records into public data, and tracking identifiers are minimised or hashed where appropriate.
Production traffic uses encrypted HTTPS connections provided by the hosting platform.
Access policies are applied close to the data, in addition to checks in the application.
Administrative access is reserved for authorised operational needs.
You keep control of the business information and contacts entrusted to your Studio.
المدفوعات
Checkout and sensitive banking onboarding are hosted by Stripe. Studio receives signed events and the operational references needed to confirm a payment, refund or dispute; it does not store card or bank account details.
مسؤولية مشتركة
We secure the platform and the services we operate. Customers and partners also protect their mailbox, devices and authorised access. The safest system is one whose responsibilities are understood.
Platform access, application updates, service configuration and investigation of reported incidents.
Accurate user access, protected email accounts and prompt reporting of suspicious activity.
Hosting, database and payment infrastructure within their respective security programmes.
إذا بدا شيء غير طبيعي
Security reports are treated separately from ordinary commercial questions so that the team can qualify the issue and limit exposure quickly.
Send the affected page, time and observable behaviour without including passwords or card details.
We assess the scope and restrict the affected access or operation when necessary.
The cause is fixed, relevant evidence is preserved and affected parties are informed when required.
Describe the context and the Studio team will route it to the right person. Never send a password, login code or payment card number.