Skip to content

Security overview

Security & Deployment Considerations

Mawidi is built with security in mind. We apply documented security controls to help protect data and patient information within the configured deployment.

Details vary with the service, account and infrastructure configured for your business. Confirm the applicable scope before moving data.

What to verify

Data Protection

Encryption controls

Connections use encryption in transit. Encryption at rest depends on the configured infrastructure and data type. This is not end-to-end encryption between end users.

Data Residency

Data location and residency depend on the configured infrastructure. Confirm the location and any residency requirements for your deployment.

Regular Backups

Backup and recovery options depend on the configured service and retention policy; confirm the exact policy for your deployment.

Data Isolation

Organization-scoped access patterns separate tenant data. Confirm the exact data boundaries and any exceptions relevant to your deployment.

Review scope and configuration

Security and compliance considerations

PDPL considerations

Review Saudi Arabia's Personal Data Protection Law (PDPL) requirements with your organisation and counsel before enabling a deployment.

GDPR considerations

Data handling should be assessed against the GDPR obligations that apply to your organisation and use case.

WhatsApp Business connection

Mawidi connects to the official WhatsApp Business platform when the required business account and provider configuration are in place.

Payment processor controls

Payment card handling is delegated to the configured payment processor; confirm the processor, account scope and applicable PCI responsibilities for your deployment.

Review scope and configuration

Security Measures

Rate Limiting

Rate limits are applied to selected routes. Coverage and thresholds vary by endpoint and deployment.

CSRF Protection

CSRF protections are applied to relevant protected forms and routes.

Content Security Policy

Content Security Policy is configured across web surfaces; the policy varies by surface and environment.

Independent assessment status

This page does not represent an independent penetration test or certification. Ask Mawidi about assessment evidence available for your review.

What to verify

Access Control

Role-Based Access

Access uses role and capability checks. Confirm the permissions assigned to each role in your workspace.

Authentication methods

User and staff sign-in may use different configured methods. Confirm the authentication methods used in your workspace.

Session Management

Session behavior follows the configured authentication provider and policy; confirm lifetimes and re-authentication requirements.

Audit Logging

Selected actions are audit-logged. Confirm event coverage and retention for your use case.

Direct contact

Security Contact

For security concerns or vulnerability reports, email the address below.

security@mawidi.com

Have Security Questions?

Contact Mawidi to discuss the security requirements for your deployment.

14-Day Free Trial
No credit card required
Response within 2 hours