Security & data protection

Systems built for data that can’t leak

Government bodies and private companies trust us with members’ records, payments, payroll and accounts. Here is exactly how the systems we build keep that data safe.

Controls

Security in every layer

  • Access control

    • Role-based permissions down to each action
    • Branch and data scope per user
    • An access matrix you can review
    • Forced password change and session control
  • Accountability

    • An Audit Log of every create, change and deletion
    • Before-and-after values kept for every change
    • Approval chains on refunds, transfers and payments
  • Data protection

    • A separate application and database for each client
    • HTTPS on every system we host
    • Passwords stored only as salted hashes
    • Contact data masked where it isn’t needed
  • Secure engineering

    • Prepared queries against SQL injection
    • Output escaping against XSS
    • CSRF protection on every form
    • Strict security headers and content policies
  • AI with guard rails

    • Read-only database access for assistants
    • Every query checked against the user’s permissions
    • Every query logged
  • Operations

    • Private source control for every project
    • Automated, reversible deployments
    • Backups and monitoring on the systems we host
    • Confidentiality agreements (NDA) with clients

In practice

An Audit Log behind every number

In the ERP we built for a ministry-affiliated club, every payment passes a treasury session, posts to the ledger automatically, and leaves a trace: who, when, and what changed. Refunds and transfers need approval before they happen.

Approval workflows in an ERP built by AL-Arcade

Questions

Frequently asked questions

Can you handle sensitive and government data?

Yes. Our systems hold members’ personal records, payments, payroll and accounts for a club affiliated with the Ministry of Youth & Sports, under role-based access, an Audit Log and approval chains.

Is our data shared with other clients?

No. Each client runs on its own application and its own database.

Can we host the system on our own servers?

Yes. We can host and run it for you, or deploy it to your own infrastructure.

Do you sign an NDA?

Yes. We sign confidentiality agreements before we see your data or documents.

Who can see what inside the system?

Exactly what their role allows. Permissions are set per role and per user, and every change is recorded in the Audit Log.