Security

Security at Sanad

How we protect billing data for organizations operating in Algeria: tenant isolation, secure sign-in, and controls built into the product.

Last updated: July 2026

Security pillars

Tenant and organization isolation

Each customer organization runs on isolated database schemas. Application queries are scoped to the active organization from session context.

  • Schema-per-tenant data separation in PostgreSQL
  • Org-scoped API access on customers, documents, and settings
  • No cross-tenant reads from application handlers

Authentication and sessions

Sign-in uses industry-standard OpenID Connect with Authorization Code and PKCE. Session tokens are protected at rest when stored server-side.

  • OIDC-based login via Dex
  • Encrypted session token storage in production configurations
  • Organization membership required before CRM access

Application controls

The platform applies baseline protections on every request and logs sensitive actions for review.

  • Content Security Policy and security headers on the web app
  • CSRF protection on state-changing API calls
  • Rate limiting and brute-force protection on authentication endpoints
  • Structured audit logging for login, document emission, and configuration changes

Billing data integrity

Financial totals and document numbering follow strict server-side rules so issued PDFs stay consistent with stored records.

  • Amounts stored as integer minor units, not floating point
  • Atomic document numbering inside database transactions
  • Idempotent PDF generation with safe retries on failure

Infrastructure

Sanad runs on managed cloud infrastructure with encrypted connections to the database and object storage for organization assets such as logos and stamps.

We use subprocessors for hosting, email delivery, and infrastructure under contractual safeguards. We do not sell workspace data.

Your responsibilities

Organization owners control who can access the workspace. Use strong credentials, limit membership to authorized staff, and review issued documents before sending them to clients.

You remain responsible for the accuracy of fiscal identifiers and totals on documents you issue.

Report a security issue

If you believe you found a vulnerability, email security-report@sanad.cloud with steps to reproduce and the affected URL or API path. We review good-faith reports promptly.

Please do not publicly disclose issues before we have had a chance to respond.

Security questions? Email security-report@sanad.cloud.

Discuss your deployment

Book a demo to review how Sanad fits your security and compliance requirements in Algeria.

Cookie preferences

We use cookies to improve your experience and (optionally) enable analytics.