Encryption controls
Connections use encryption in transit. Encryption at rest depends on the configured infrastructure and data type. This is not end-to-end encryption between end users.
Security overview
Mawidi is built with security in mind. We apply documented security controls to help protect data and patient information within the configured deployment.
Details vary with the service, account and infrastructure configured for your business. Confirm the applicable scope before moving data.
What to verify
Connections use encryption in transit. Encryption at rest depends on the configured infrastructure and data type. This is not end-to-end encryption between end users.
Data location and residency depend on the configured infrastructure. Confirm the location and any residency requirements for your deployment.
Backup and recovery options depend on the configured service and retention policy; confirm the exact policy for your deployment.
Organization-scoped access patterns separate tenant data. Confirm the exact data boundaries and any exceptions relevant to your deployment.
Review scope and configuration
Review Saudi Arabia's Personal Data Protection Law (PDPL) requirements with your organisation and counsel before enabling a deployment.
Data handling should be assessed against the GDPR obligations that apply to your organisation and use case.
Mawidi connects to the official WhatsApp Business platform when the required business account and provider configuration are in place.
Payment card handling is delegated to the configured payment processor; confirm the processor, account scope and applicable PCI responsibilities for your deployment.
Review scope and configuration
Rate limits are applied to selected routes. Coverage and thresholds vary by endpoint and deployment.
CSRF protections are applied to relevant protected forms and routes.
Content Security Policy is configured across web surfaces; the policy varies by surface and environment.
This page does not represent an independent penetration test or certification. Ask Mawidi about assessment evidence available for your review.
What to verify
Access uses role and capability checks. Confirm the permissions assigned to each role in your workspace.
User and staff sign-in may use different configured methods. Confirm the authentication methods used in your workspace.
Session behavior follows the configured authentication provider and policy; confirm lifetimes and re-authentication requirements.
Selected actions are audit-logged. Confirm event coverage and retention for your use case.
Direct contact
For security concerns or vulnerability reports, email the address below.
Contact Mawidi to discuss the security requirements for your deployment.