Skip to content
Security & trust

Thoughtful protection for the data your community entrusts to you.

Makatib.App handles education records concerning children and families. Security and privacy are built into how the service controls access, processes payments, delivers changes and responds when something needs attention.

Our safeguards

Layers of protection, from sign-in to release.

No single control carries the whole load. We combine technical boundaries, operational processes and secure delivery practices.

Access

Tenant and role isolation

Every record is scoped to one madrassa. Role-based permissions and database row-level security restrict what management, teachers and guardians can access.

Protection

Encryption and secrets

Connections are protected with TLS, stored data uses provider-managed encryption at rest, and production credentials are managed outside the source-code repository.

Payments

Payment details stay with Stripe

Card and bank details are entered directly into Stripe-hosted payment flows. Makatib.App receives payment outcomes, not complete payment credentials.

Delivery

Security throughout development

Changes pass code review and automated lint, type, test and production-build checks. Application code and dependencies are also subject to automated security scanning.

Resilience

Backups and monitored operations

Managed infrastructure backups support service recovery. Important payment, messaging and background-job failures are logged and monitored for investigation.

Response

Incident and access procedures

Documented procedures cover containment, investigation, customer communication, recovery and access removal. Security events are recorded and followed through to corrective action.

Least privilege

People see what their role requires.

Application permissions and database policies work together to enforce the boundary, including if a request bypasses the visible interface.

Management

Access is limited to the madrassa they administer, including its staff, classes and operational records.

Teachers

Access is restricted to the students and classes they are authorised to teach, with sensitive management information kept separate.

Guardians

Access is restricted to children linked to their own account and the information intended for families.

Clear commitments

Your data is not our product.

Madrassas remain in control of the records they put into Makatib.App. We process those records to provide the service and according to the customer's instructions.

  • We do not sell personal data.
  • We do not use student data for advertising.
  • We do not use student data to train AI models.
  • Children do not create accounts or sign in.
Transparency

Review the detail.

Our public documents explain how we handle personal data, the providers that support the service and the contractual safeguards available to madrassas.

Report a security concern

If you believe you have found a security issue, please report it privately and include enough detail for us to understand and reproduce the problem. Do not access, change or retain other people's data while investigating.

info@makatib.app

For privacy rights or data-protection questions, contact privacy@makatib.app.