simdar
عربيEN

Trust & Security

Last updated August 2026

Our commitment

Your business data is your livelihood. We treat it with the seriousness that deserves. This page explains, in plain language, how simdar protects your data, which infrastructure partners we rely on, and what you can do to protect yourself.

We believe in transparency: you should know exactly where your data lives, who can access it, and what we do to keep it safe. No vague promises — here are the specifics.

Where your data lives

simdar runs on industry-leading infrastructure from trusted, globally recognised technology companies. We chose our partners based on their security track records, compliance certifications, and the maturity of their platforms — not just cost or convenience.

Database — Supabase

All your business data — customer records, invoices, quotes, jobs, conversations, and messages — is stored in a managed PostgreSQL database hosted by Supabase. Supabase is SOC 2 Type II certified, meaning an independent auditor has verified that their security controls are properly designed and operating effectively over time.

Your data is encrypted at rest using AES-256 encryption, and all connections to the database are encrypted in transit using TLS 1.2 or higher. Supabase maintains automated backups, point-in-time recovery, and infrastructure redundancy.

Supabase's data centres are located in the United States and are operated by Amazon Web Services (AWS), one of the most widely trusted cloud platforms in the world. AWS infrastructure meets a broad set of international compliance standards including SOC 1/2/3, ISO 27001, and more.

Application hosting — Vercel

The simdar web application is hosted on Vercel's global edge network. Vercel is SOC 2 Type II certified and provides automatic HTTPS for all traffic, built-in DDoS protection, and zero-downtime deployments.

Vercel serves content from the edge location closest to your device, which means fast load times whether you're in Riyadh, Beirut, Dubai, or Cairo. All traffic is encrypted with TLS, and Vercel's infrastructure is built on top of AWS and other tier-one cloud providers.

Vercel hosts some of the most visited websites and applications in the world, including products from companies like OpenAI, The Washington Post, and Nintendo.

How we protect your data

Security is not a single feature — it is a set of practices woven through every layer of the system.

Tenant isolation

Every business on simdar is a separate tenant. Your data is isolated from every other business's data at the database level using PostgreSQL row-level security (RLS). This means access control is enforced by the database engine itself, not by application code. Even if a bug existed in the application layer, the database would still prevent one business from seeing another's data.

Every query your browser makes passes through RLS policies that verify your identity and your business affiliation before returning a single row. There are no exceptions and no overrides in the client-facing code.

Authentication

simdar uses phone-based one-time passwords (OTP) for authentication. There are no traditional passwords to leak, be guessed, reused across services, or stolen in a phishing attack. Each verification code is short-lived, single-use, and delivered to your phone through a secure channel.

Verification codes are delivered through WhatsApp or Telegram — the same channels your business already uses — rather than SMS. This avoids SIM-swapping attacks, which are the primary vulnerability of SMS-based authentication.

Encryption

All data in transit between your device and simdar is encrypted with TLS (HTTPS). All data stored in the database is encrypted at rest. Backups are also encrypted.

simdar does not implement its own cryptographic systems. We rely on the battle-tested encryption provided by our infrastructure partners (Supabase/AWS for data at rest, TLS for data in transit). Rolling your own cryptography is a risk; using proven, audited systems is a security decision.

No customer media storage

simdar does not store any media (photos, voice notes, videos, documents) that your customers share through messaging channels. Media stays on WhatsApp's and Telegram's servers — platforms that are purpose-built for secure media storage at scale.

This is a deliberate architectural decision. By not holding customer media, simdar eliminates an entire category of data breach risk. If simdar's systems were ever compromised, no customer photos, voice messages, or files would be exposed, because we simply do not have them.

Principle of least privilege

simdar uses three different database clients with three different permission levels. Browser-facing code uses the most restricted client, which can only see data belonging to the authenticated user's business. Server-side operations use a moderately privileged client. Administrative operations use a fully privileged client, but only after explicit verification.

No single key or credential has unrestricted access to all data. This layered approach means that even if one access point were compromised, the blast radius would be limited.

Messaging infrastructure

When you connect a messaging channel like WhatsApp or Telegram to simdar, messages flow through those platforms' own infrastructure. Here's what that means for your data:

WhatsApp Cloud API

WhatsApp messages sent and received through simdar travel through Meta's WhatsApp Cloud API, which is hosted on Meta's global infrastructure in the United States. The Cloud API is Meta's official, enterprise-grade interface for business messaging.

WhatsApp provides end-to-end encryption for message content between your business and your customers. Metadata (who messaged whom, when, delivery receipts) is processed by Meta in accordance with their business terms.

The WhatsApp Cloud API is the same infrastructure used by major banks, airlines, healthcare providers, and governments worldwide for business communications. It is subject to Meta's enterprise security standards and compliance certifications.

Telegram Bot API

Telegram messages flow through Telegram's cloud infrastructure. Telegram uses client-server encryption by default, with data distributed across multiple data centres in different jurisdictions.

Telegram's Bot API is their official interface for business and developer integrations, used by millions of bots serving hundreds of millions of users.

Important recommendation: use WhatsApp Business

We strongly recommend that you use a WhatsApp Business account with simdar — not your personal WhatsApp. This is important for several reasons:

  • Separation of concerns — your personal conversations, family photos, and private messages should be completely separate from your business communications. A WhatsApp Business account creates that boundary.
  • Compliance — WhatsApp's terms of service require that commercial messaging be conducted through a Business account. Using a personal account for business purposes may violate those terms and could result in your account being restricted or banned by WhatsApp.
  • Professional identity — WhatsApp Business accounts display your business name, address, hours, and description. Your customers see a verified business, not a random phone number.
  • Business features — WhatsApp Business includes features designed for commercial use: catalogues, quick replies, labels, and automated messages. These features are not available on personal accounts.
  • simdar compatibility — simdar is designed and tested to work with WhatsApp Business accounts. While it may technically work with a personal account in manual mode, we cannot guarantee the experience or protect you from WhatsApp enforcement actions.

Setting up a WhatsApp Business account is free and takes minutes. You can use a separate phone number or, in some cases, convert your existing number. We recommend using a dedicated business number for the cleanest separation.

simdar is not responsible for any action that WhatsApp, Meta, or any messaging platform takes against your account. Using the right type of account for business messaging is the single most important thing you can do to protect yourself.

What we do not do

Clarity about what we do not do is as important as what we do:

  • We do not sell your data or your customers' data, to anyone, for any reason.
  • We do not use your data for advertising, profiling, or behavioural tracking.
  • We do not share your data with data brokers, marketing platforms, or any third party beyond the infrastructure providers listed above.
  • We do not use analytics trackers, tracking pixels, or third-party cookies.
  • We do not store customer media (photos, voice notes, videos, documents).
  • We do not train AI models on your data.
  • We do not access your data except to provide the service and to debug issues when you ask for support.
  • We do not monetise your data in any way. Our revenue comes from subscription plans, not from data.

Your responsibilities

Security is a shared responsibility. simdar protects the platform; here is what you can do to protect your business:

  • Use a WhatsApp Business account, not your personal WhatsApp, for all business messaging through simdar.
  • Keep your phone number secure. Your phone number is your login credential — if someone gains access to your phone or SIM, they could access your account.
  • Do not share verification codes. simdar will never ask you for a verification code outside of the login screen.
  • Review your customer data periodically. Remove records you no longer need. The less data you store, the less there is to protect.
  • Use a strong screen lock on your phone. Since simdar is a mobile-first application, your phone's lock screen is a critical layer of defence.
  • Inform your customers about how you use their data. As the data controller for your customers' information, you have a legal and ethical obligation to be transparent about data handling.

Incident response

If a security incident occurs — a breach, unauthorised access, or data exposure — we will act immediately:

  • We will investigate and contain the incident as quickly as possible.
  • We will notify affected users within 72 hours of confirming a breach, with a clear description of what happened, what data was affected, and what we are doing about it.
  • We will cooperate with relevant authorities as required by law.
  • We will publish a post-incident report describing the root cause, the remediation, and the steps taken to prevent recurrence.

We have never experienced a data breach. We work to keep it that way by investing in prevention, not just response.

A note on American infrastructure

simdar's infrastructure partners — Supabase, Vercel, and WhatsApp Cloud API — operate primarily from data centres in the United States. We are transparent about this because we believe you should know where your data physically resides.

We chose American infrastructure providers because they offer the highest levels of security certification (SOC 2 Type II, ISO 27001), the most mature operations teams, the broadest compliance coverage, and the most reliable uptime guarantees available today. These providers host critical data for millions of businesses worldwide, including financial institutions, healthcare organisations, and government agencies.

Data in transit between your device (wherever you are in the world) and our servers is always encrypted. Data at rest in the database is encrypted. Row-level security ensures that only your business can access your data, regardless of where the server is physically located.

If regulatory requirements in your jurisdiction impose specific data residency obligations, please contact us to discuss your needs.

Compliance

simdar supports your compliance obligations without claiming to fulfil them on your behalf:

  • Tax compliance — configurable VAT categories (standard, zero-rated, exempt, out-of-scope) with per-country regime resolution. Sequential invoice numbering that meets audit requirements. Support for simplified (B2C) and standard (B2B) invoice types as required by Gulf tax authorities.
  • E-invoicing readiness — the data model includes fields for ZATCA (Saudi Arabia), PINT AE (UAE), and Egyptian Tax Authority e-invoicing standards. These capabilities will be activated as regulations come into force.
  • Data protection — data minimisation by design, no media storage, row-level tenant isolation, full deletion capability, and data access/export on request. These practices align with the principles of major data protection frameworks.
  • Messaging compliance — we surface WhatsApp's session window rules and template requirements in the interface, so you can comply with platform policies without having to remember them.

simdar is a tool, not a compliance authority. We give you the infrastructure to comply, but the responsibility for compliance with local tax laws, data protection regulations, and messaging platform terms remains yours. When in doubt, consult a qualified professional.

Continuous improvement

Security is not a destination. We continuously review and improve our practices:

  • We monitor our infrastructure providers' security advisories and apply relevant updates promptly.
  • We review and tighten our row-level security policies as new features are added.
  • We audit access patterns and investigate anomalies.
  • We follow responsible disclosure practices and welcome security reports from the community.

This page will be updated as our security practices evolve. If you have questions about anything described here, contact us at the email below.

Our infrastructure partners

S
Supabase
SOC 2 Type II certified. Managed PostgreSQL with row-level security, encryption at rest and in transit, and real-time subscriptions. Trusted by hundreds of thousands of applications worldwide.
V
Vercel
SOC 2 Type II certified. Global edge network with automatic HTTPS, DDoS protection, and zero-downtime deployments. Hosts some of the most visited websites in the world.
M
Meta / WhatsApp Cloud API
Enterprise-grade messaging infrastructure operated by Meta. End-to-end encryption for message content. Business API with verified sender identity and compliance controls.
T
Telegram Bot API
Cloud-based messaging with encrypted transit. Client-to-server encryption by default with optional end-to-end encryption for private chats.

Security contact

If you discover a vulnerability or have a security concern, contact us. We take every report seriously and respond within 48 hours.

security@simdar.app