Security
How the platform is built and operated, what we commit to, and how to tell us about a vulnerability.
- Encryption in transit and at rest is on by default and cannot be switched off.
- Databases and storage have no public endpoint unless you open one deliberately.
- Staff access to customer environments is scoped, time-limited, and logged.
- Report a vulnerability to security@darwa.com — we reply within 24 hours and never pursue good-faith researchers.
Encryption
- TLS 1.2 or higher for every external connection, with HSTS on all our domains.
- AES-256 at rest for volumes, object storage, backups, and snapshots.
- Database connections require TLS. Certificates are issued and rotated by the platform.
- Secrets are encrypted with per-tenant keys, decrypted only inside the running workload.
Isolation
Every workload runs in its own namespace with its own network policy. Services reach each other over a private network scoped to your project; nothing is reachable across tenants. Dedicated instances get dedicated CPU and memory rather than shared capacity.
Staff access
Production access requires hardware-backed multi-factor authentication and is granted per task, not standing. Sessions are time-limited and recorded. Access to customer content requires a support request from you or a documented incident, and is written to an audit trail available on request.
Scanning and hardening
- Dependency advisories checked on every build; builds fail on committed secrets.
- Uploads to object storage are scanned for malware before becoming readable.
- Base images are rebuilt and patched weekly, and on disclosure of a critical CVE.
- Edge absorbs volumetric attacks; per-route rate limiting is available to every service.
Backups and continuity
Databases are backed up daily with point-in-time recovery across the retention window on your plan. Restores land in a new instance so you can verify them before promoting. We test restore procedures monthly and publish the result of the most recent test on request.
Incident response
We aim to acknowledge a confirmed security incident affecting your data within 24 hours and to give a written account with impact and remediation within 72 hours. Availability incidents are posted at status.darwa.com as they are being handled, not after.
Compliance
SOC 2 Type II is in progress with a target of Q2 2027; we will not claim it before the report exists. We support GDPR and UAE PDPL obligations today through the DPA, including regional data residency and sub-processor disclosure. Penetration tests are performed annually by an external firm and a summary letter is available under NDA.
Vulnerability disclosure
Send findings to security@darwa.com, encrypted with the key at darwa.com/.well-known/pgp if you prefer. Include enough detail to reproduce. We reply within 24 hours, keep you updated, and credit you if you want the credit.
We will not pursue legal action for good-faith research that avoids privacy violations, data destruction, service degradation, and access to accounts that are not yours. Automated scanning against production and social engineering of our staff are out of scope.
What is yours to secure
Application code, access control inside your app, who you invite to your organisation, and what your agents are permitted to do remain your responsibility. The split is set out in the Shared Responsibility Model.
Contact
Darwa Technologies FZ-LLC, Dubai Internet City, Dubai, United Arab Emirates. Written notice may be sent to legal@darwa.com. Security reports go to security@darwa.com. Privacy requests go to privacy@darwa.com.