11Trust & contact
Security
Tajir Global Limited · contact@utajir.com
On this page
- Security scope & governance
- Identity & account protection
- Infrastructure & tenant isolation
- Encryption, secrets & data lifecycle
- Secure development & vulnerabilities
- Personnel & service providers
- Backups, recovery & continuity
- Incident detection, response & notification
- Security evidence & enterprise requests
- Responsible vulnerability disclosure
Security scope & governance
1.1Scope of this security page
This page explains responsibility for protecting Utajir Services and the limits of the security information provided. Contractual commitments are in the Terms, DPA, security annex and any accepted SLA. The page is not a compliance certificate, independent test report or guarantee against interruption or intrusion, and does not replace implementation of controls required for the enabled service.
1.2Responsibility and risk assessment
Tajir Global Limited is responsible for protecting the systems and data it operates and assigning internal responsibility for risks and incidents. You manage user permissions, account settings and lawful content; an Agency explains what it manages for clients. This allocation does not excuse Utajir’s own faults or obligations. Measures are reviewed as data, functions or providers change.
Identity & account protection
2.1Account protection
Use separately authorized access for each user, protect credentials and never send them in support. Enable additional verification where available and remove unnecessary permissions and sessions through available tools. Authentication and sign-in functions depend on the offered service and plan; a subscription does not promise every verification or single-sign-on method in every plan.
2.2Administration and delegation
Administrator, support and contractor permissions are assessed on need, with evidence of grants and revocation and appropriate controls for sensitive actions. Subscription ownership does not grant an Agency unrestricted rights to every client's data. Recovery and ownership transfer must prevent access being handed to someone possessing only superficial information.
Infrastructure & tenant isolation
3.1Account and environment isolation
We undertake to enforce account authorization boundaries for reading, modification, export, files, APIs and background operations, with appropriate separation of development, testing and customer processing under the security annex. A different account name or page address alone is not a safeguard. An Agency subscription does not authorize access to an account it lacks valid authority to administer.
3.2Infrastructure and monitoring
Provider information identifies service scope and processing countries. Infrastructure administration and access are restricted by need and authority, with risk-based protection against unauthorized access, disruption and abusive load. Hosting a component with a known provider does not give every Utajir component that provider’s certifications or properties. Request service-scope information at contact@utajir.com.
Encryption, secrets & data lifecycle
4.1Encryption and secrets
The security annex commits to appropriate encryption of customer-data transmission over public networks and controlled access to data, keys and tokens. A browser’s secure-connection indicator does not mean all stored data is encrypted or that encryption is end-to-end. A specific algorithm or storage or backup coverage is stated only in the relevant service description; contracted protection scope may be requested without revealing operational secrets.
4.2Data lifecycle
Data, attachments and support copies are minimized to purpose, with controlled export, deletion and authority. Deletion must reach active copies and providers under the approved schedule; deferred copies remain isolated and deletion is reapplied on restoration. Retention and rights follow the Privacy Policy and DPA; hiding an interface record is not evidence of final deletion.
Secure development & vulnerabilities
5.1Development review
Changes affecting permissions, data, files or external actions require checks proportionate to their impact. Dependencies and advisories are assessed for applicability and remediation; advisory counts alone do not count exploitable vulnerabilities. Test-environment or historical results do not establish security of a different production version.
5.2Prioritization and evidence
We assess vulnerabilities by exploitability, impact and actual exposure and track suitable remediation or mitigation. We do not claim closure of every vulnerability or a comprehensive independent penetration test. Any fixed remediation deadline requires express agreement identifying severity and service scope, without limiting duties to take necessary measures and give required notices for an actual risk.
Personnel & service providers
6.1Staff and contractors
Protection includes suitable confidentiality obligations and role-specific training for people with data access and access review on joining, role change or departure. Devices, remote access and file transfer are assessed proportionately to risk. Background checks or a particular training frequency are not assumed without approved procedures and a lawful basis.
6.2Suppliers and responsibility boundaries
Suppliers are assessed for service, data, countries, safeguards and contract, and verified on-behalf providers appear in the Subprocessor Register. A supplier's certification does not automatically certify Utajir or every component. Provider, access and incident changes follow the DPA; outsourcing a function does not by itself end our responsibility.
Backups, recovery & continuity
7.1Backups and recovery
The service description or SLA, if any, identifies data covered by backup, restoration method and targets. This page promises no daily backup, immediate restoration or maximum data-loss interval. Backups we retain remain subject to the security annex and the DPA’s deletion limit of 90 days after active-copy deletion; temporary retention does not authorize a new use.
7.2Continuity and customer responsibilities
Continuity planning assesses service or provider failures, communication and recovery methods and external dependencies. Customers maintain suitable copies of exportable data for their needs; this does not excuse our contracted backup obligations. Any recovery target or availability commitment must have a defined contractual scope, exceptions and measurement method.
Incident detection, response & notification
8.1Assessment and containment
Incident handling includes validating reports, identifying systems, data and impact, containment, necessary evidence preservation, investigation and remediation. We distinguish availability faults from personal data breaches and follow the relevant notification process. Reports go to contact@utajir.com; request a secure method for sensitive details and do not include account secrets.
8.2Notification and lessons learned
For customer data processing, breach notices, updates and assistance follow the DPA without undue delay; authority and individual duties depend on law and role. Agency coordination must not conceal necessary information from the controller, and awaiting a final report does not postpone a required initial notice. Causes and measures are reviewed to prevent recurrence while protecting details that could enable ongoing exploitation.
Security evidence & enterprise requests
9.1What can be evidenced
In this release, Tajir Global Limited makes no claim that Utajir holds ISO 27001 certification, a SOC 2 report or sector accreditation. Any later report or certification identifies entity, system, period, issuer and coverage limits. A provider’s certification does not certify the entire platform, and describing measures does not guarantee compliance with every law or the impossibility of an incident.
9.2Enterprise enquiries
Security information or questionnaires may be requested through the approved channel after need and authority are identified. We provide suitable existing evidence or identify what remains unverified, using confidentiality arrangements where needed. A questionnaire response does not automatically amend the contract; new commitments or service levels require authorized written agreement.
Responsible vulnerability disclosure
10.1Reporting a vulnerability
Send contact@utajir.com a description, affected component, discovery time, limited reproduction steps and potential impact, without passwords, tokens or unnecessary customer data. If unauthorized data appears, stop further access and do not download it to establish scale. Request a secure channel before sending sensitive evidence or dangerous material.
10.2Testing and disclosure boundaries
This page does not grant blanket authorization to intrude, disrupt service or test external providers, or promise rewards or legal immunity. Written scope must precede testing beyond ordinary use of your own account. We assess good-faith reports and coordinate remediation and responsible disclosure according to risk and law without requiring surrender of legal rights or preventing lawful contact with competent authorities.