KAAMYAB

Security

Updated 03 Oct 2026

How we protect your data

  • Encryption: HTTPS everywhere with HSTS. Job-site passwords and browser sessions are encrypted at rest (Fernet / AES-128). Passwords for Kaamyab are hashed with PBKDF2-SHA256.
  • Access control: each user's data is isolated by an automatic database filter. Administrators use separate accounts with roles, mandatory two-factor authentication and an audit log; an admin who views your account must give a reason, which is logged.
  • Application security: strict Content-Security-Policy, CSRF protection, rate limits and account lockout, file-type checks on uploads, automated security tests on every code change (secret scanning, dependency CVEs, static analysis, live attack checks).
  • Data minimisation: AI helpers receive only the facts they need; logs are scrubbed of emails, phone numbers, OTPs and secrets.
  • Reporting a vulnerability: write to [PRIVACY EMAIL]. Please give us reasonable time to fix before disclosure.