TajirPro
Business Operating System
TajirPro Trust Center

Security Policy

The shared security responsibilities and controls used to protect TajirPro.

Effective: 05 August 2026 Last updated: 06 August 2026 Version: 1.0 Operator: TajirPro Jurisdiction: Pakistan

Legal contact: support@tajirpro.net

1. Security programme

TajirPro applies layered technical and organisational measures proportionate to the service, including secure transport, credential protection, permissions, logging, monitoring, backups, updates, and controlled support access. Controls evolve as risks, technology, and the platform change.

2. Authentication and credentials

Passwords are stored using secure one-way hashing supported by the application framework. OTPs and sessions are time-limited. Users must use strong unique passwords, protect email and devices, avoid shared credentials, and immediately remove access for staff who leave or change roles.

3. Access control

Company data is separated through application access controls and role permissions. Owners are responsible for assigning appropriate staff rights. Temporary support access, where available, should be authorised, time-limited, read-only where practical, and auditable.

4. Monitoring and response

Login events, sessions, sensitive actions, and system health may be logged to detect abuse and investigate incidents. Automated protection may throttle, challenge, block, or terminate suspicious activity.

5. Vulnerability and patch management

Security fixes are prioritised according to risk. Emergency changes may be deployed without advance notice. Unsupported browsers, devices, server configurations, custom modifications, or delayed deployment by a white-label operator can reduce security.

6. Customer responsibilities

Customers must control staff access, review audit logs, keep contact details current, install device and browser updates, maintain endpoint protection, verify exports, avoid phishing, and report anomalies promptly.

7. No absolute guarantee

Security measures reduce but cannot eliminate risk. Zero-day vulnerabilities, sophisticated attacks, compromised user devices, insider misuse, provider failure, and events beyond reasonable control may still cause disruption or loss.

8. Reporting a concern

Security concerns should be reported privately through Support with the affected account, time, steps, and evidence. Do not publicly disclose exploitable details or access data that does not belong to you.

This policy forms part of the TajirPro customer agreement. Mandatory rights under applicable law continue to apply even where a clause states “to the maximum extent permitted by law.”
Contact support →