Skip to content
  • 03Agencies
  • 04Pricing
العربية
Join utajir
utajir/Legal center/Security
Version 2026-09-15.2
All documents

11Trust & contact

Security

Tajir Global Limited · contact@utajir.com

10 sectionsRelease date: 2026-09-15Archived Arabic and English copy
On this page
  1. Security scope & governance
  2. Identity & account protection
  3. Infrastructure & tenant isolation
  4. Encryption, secrets & data lifecycle
  5. Secure development & vulnerabilities
  6. Personnel & service providers
  7. Backups, recovery & continuity
  8. Incident detection, response & notification
  9. Security evidence & enterprise requests
  10. Responsible vulnerability disclosure
01

Security scope & governance#

1.1Scope of this security page

This page explains responsibility for protecting Utajir Services and the limits of the security information provided. Contractual commitments are in the Terms, DPA, security annex and any accepted SLA. The page is not a compliance certificate, independent test report or guarantee against interruption or intrusion, and does not replace implementation of controls required for the enabled service.

1.2Responsibility and risk assessment

Tajir Global Limited is responsible for protecting the systems and data it operates and assigning internal responsibility for risks and incidents. You manage user permissions, account settings and lawful content; an Agency explains what it manages for clients. This allocation does not excuse Utajir’s own faults or obligations. Measures are reviewed as data, functions or providers change.

02

Identity & account protection#

2.1Account protection

Use separately authorized access for each user, protect credentials and never send them in support. Enable additional verification where available and remove unnecessary permissions and sessions through available tools. Authentication and sign-in functions depend on the offered service and plan; a subscription does not promise every verification or single-sign-on method in every plan.

2.2Administration and delegation

Administrator, support and contractor permissions are assessed on need, with evidence of grants and revocation and appropriate controls for sensitive actions. Subscription ownership does not grant an Agency unrestricted rights to every client's data. Recovery and ownership transfer must prevent access being handed to someone possessing only superficial information.

03

Infrastructure & tenant isolation#

3.1Account and environment isolation

We undertake to enforce account authorization boundaries for reading, modification, export, files, APIs and background operations, with appropriate separation of development, testing and customer processing under the security annex. A different account name or page address alone is not a safeguard. An Agency subscription does not authorize access to an account it lacks valid authority to administer.

3.2Infrastructure and monitoring

Provider information identifies service scope and processing countries. Infrastructure administration and access are restricted by need and authority, with risk-based protection against unauthorized access, disruption and abusive load. Hosting a component with a known provider does not give every Utajir component that provider’s certifications or properties. Request service-scope information at contact@utajir.com.

04

Encryption, secrets & data lifecycle#

4.1Encryption and secrets

The security annex commits to appropriate encryption of customer-data transmission over public networks and controlled access to data, keys and tokens. A browser’s secure-connection indicator does not mean all stored data is encrypted or that encryption is end-to-end. A specific algorithm or storage or backup coverage is stated only in the relevant service description; contracted protection scope may be requested without revealing operational secrets.

4.2Data lifecycle

Data, attachments and support copies are minimized to purpose, with controlled export, deletion and authority. Deletion must reach active copies and providers under the approved schedule; deferred copies remain isolated and deletion is reapplied on restoration. Retention and rights follow the Privacy Policy and DPA; hiding an interface record is not evidence of final deletion.

05

Secure development & vulnerabilities#

5.1Development review

Changes affecting permissions, data, files or external actions require checks proportionate to their impact. Dependencies and advisories are assessed for applicability and remediation; advisory counts alone do not count exploitable vulnerabilities. Test-environment or historical results do not establish security of a different production version.

5.2Prioritization and evidence

We assess vulnerabilities by exploitability, impact and actual exposure and track suitable remediation or mitigation. We do not claim closure of every vulnerability or a comprehensive independent penetration test. Any fixed remediation deadline requires express agreement identifying severity and service scope, without limiting duties to take necessary measures and give required notices for an actual risk.

06

Personnel & service providers#

6.1Staff and contractors

Protection includes suitable confidentiality obligations and role-specific training for people with data access and access review on joining, role change or departure. Devices, remote access and file transfer are assessed proportionately to risk. Background checks or a particular training frequency are not assumed without approved procedures and a lawful basis.

6.2Suppliers and responsibility boundaries

Suppliers are assessed for service, data, countries, safeguards and contract, and verified on-behalf providers appear in the Subprocessor Register. A supplier's certification does not automatically certify Utajir or every component. Provider, access and incident changes follow the DPA; outsourcing a function does not by itself end our responsibility.

07

Backups, recovery & continuity#

7.1Backups and recovery

The service description or SLA, if any, identifies data covered by backup, restoration method and targets. This page promises no daily backup, immediate restoration or maximum data-loss interval. Backups we retain remain subject to the security annex and the DPA’s deletion limit of 90 days after active-copy deletion; temporary retention does not authorize a new use.

7.2Continuity and customer responsibilities

Continuity planning assesses service or provider failures, communication and recovery methods and external dependencies. Customers maintain suitable copies of exportable data for their needs; this does not excuse our contracted backup obligations. Any recovery target or availability commitment must have a defined contractual scope, exceptions and measurement method.

08

Incident detection, response & notification#

8.1Assessment and containment

Incident handling includes validating reports, identifying systems, data and impact, containment, necessary evidence preservation, investigation and remediation. We distinguish availability faults from personal data breaches and follow the relevant notification process. Reports go to contact@utajir.com; request a secure method for sensitive details and do not include account secrets.

8.2Notification and lessons learned

For customer data processing, breach notices, updates and assistance follow the DPA without undue delay; authority and individual duties depend on law and role. Agency coordination must not conceal necessary information from the controller, and awaiting a final report does not postpone a required initial notice. Causes and measures are reviewed to prevent recurrence while protecting details that could enable ongoing exploitation.

09

Security evidence & enterprise requests#

9.1What can be evidenced

In this release, Tajir Global Limited makes no claim that Utajir holds ISO 27001 certification, a SOC 2 report or sector accreditation. Any later report or certification identifies entity, system, period, issuer and coverage limits. A provider’s certification does not certify the entire platform, and describing measures does not guarantee compliance with every law or the impossibility of an incident.

9.2Enterprise enquiries

Security information or questionnaires may be requested through the approved channel after need and authority are identified. We provide suitable existing evidence or identify what remains unverified, using confidentiality arrangements where needed. A questionnaire response does not automatically amend the contract; new commitments or service levels require authorized written agreement.

10

Responsible vulnerability disclosure#

10.1Reporting a vulnerability

Send contact@utajir.com a description, affected component, discovery time, limited reproduction steps and potential impact, without passwords, tokens or unnecessary customer data. If unauthorized data appears, stop further access and do not download it to establish scale. Request a secure channel before sending sensitive evidence or dangerous material.

10.2Testing and disclosure boundaries

This page does not grant blanket authorization to intrude, disrupt service or test external providers, or promise rewards or legal immunity. Written scope must precede testing beyond ordinary use of your own account. We assess good-faith reports and coordinate remediation and responsible disclosure according to risk and law without requiring surrender of legal rights or preventing lawful contact with competent authorities.

End of document
Previous documentReferrals & commissionsNext documentRequests & reports

On this page

  1. 01Security scope & governance
  2. 02Identity & account protection
  3. 03Infrastructure & tenant isolation
  4. 04Encryption, secrets & data lifecycle
  5. 05Secure development & vulnerabilities
  6. 06Personnel & service providers
  7. 07Backups, recovery & continuity
  8. 08Incident detection, response & notification
  9. 09Security evidence & enterprise requests
  10. 10Responsible vulnerability disclosure
Questions or corrections:
contact@utajir.com

Tajir Global Limited · contact@utajir.com

Back to top