Security Policy
The shared security responsibilities and controls used to protect TajirPro.
Legal contact: support@tajirpro.net
1. Security programme
TajirPro applies layered technical and organisational measures proportionate to the service, including secure transport, credential protection, permissions, logging, monitoring, backups, updates, and controlled support access. Controls evolve as risks, technology, and the platform change.
2. Authentication and credentials
Passwords are stored using secure one-way hashing supported by the application framework. OTPs and sessions are time-limited. Users must use strong unique passwords, protect email and devices, avoid shared credentials, and immediately remove access for staff who leave or change roles.
3. Access control
Company data is separated through application access controls and role permissions. Owners are responsible for assigning appropriate staff rights. Temporary support access, where available, should be authorised, time-limited, read-only where practical, and auditable.
4. Monitoring and response
Login events, sessions, sensitive actions, and system health may be logged to detect abuse and investigate incidents. Automated protection may throttle, challenge, block, or terminate suspicious activity.
5. Vulnerability and patch management
Security fixes are prioritised according to risk. Emergency changes may be deployed without advance notice. Unsupported browsers, devices, server configurations, custom modifications, or delayed deployment by a white-label operator can reduce security.
6. Customer responsibilities
Customers must control staff access, review audit logs, keep contact details current, install device and browser updates, maintain endpoint protection, verify exports, avoid phishing, and report anomalies promptly.
7. No absolute guarantee
Security measures reduce but cannot eliminate risk. Zero-day vulnerabilities, sophisticated attacks, compromised user devices, insider misuse, provider failure, and events beyond reasonable control may still cause disruption or loss.
8. Reporting a concern
Security concerns should be reported privately through Support with the affected account, time, steps, and evidence. Do not publicly disclose exploitable details or access data that does not belong to you.