Tenant and role isolation
Every record is scoped to one madrassa. Role-based permissions and database row-level security restrict what management, teachers and guardians can access.
Makatib.App handles education records concerning children and families. Security and privacy are built into how the service controls access, processes payments, delivers changes and responds when something needs attention.
No single control carries the whole load. We combine technical boundaries, operational processes and secure delivery practices.
Every record is scoped to one madrassa. Role-based permissions and database row-level security restrict what management, teachers and guardians can access.
Connections are protected with TLS, stored data uses provider-managed encryption at rest, and production credentials are managed outside the source-code repository.
Card and bank details are entered directly into Stripe-hosted payment flows. Makatib.App receives payment outcomes, not complete payment credentials.
Changes pass code review and automated lint, type, test and production-build checks. Application code and dependencies are also subject to automated security scanning.
Managed infrastructure backups support service recovery. Important payment, messaging and background-job failures are logged and monitored for investigation.
Documented procedures cover containment, investigation, customer communication, recovery and access removal. Security events are recorded and followed through to corrective action.
Application permissions and database policies work together to enforce the boundary, including if a request bypasses the visible interface.
Access is limited to the madrassa they administer, including its staff, classes and operational records.
Access is restricted to the students and classes they are authorised to teach, with sensitive management information kept separate.
Access is restricted to children linked to their own account and the information intended for families.
Madrassas remain in control of the records they put into Makatib.App. We process those records to provide the service and according to the customer's instructions.
Our public documents explain how we handle personal data, the providers that support the service and the contractual safeguards available to madrassas.
If you believe you have found a security issue, please report it privately and include enough detail for us to understand and reproduce the problem. Do not access, change or retain other people's data while investigating.
info@makatib.appFor privacy rights or data-protection questions, contact privacy@makatib.app.