Security

How we protect your data and infrastructure

A Saudi hosting platform built on plain operational practices: hosting inside the Kingdom, encryption on every domain, tenant isolation, and continuous backups and monitoring. This page describes what we actually do — without overstatement.

Independently verifiable

Security posture — publicly verifiable

Our security posture is checked by independent public tools — verify it yourself via the links below.

  • HTTPS enforced on every page
  • HSTS enabled (preload)
  • Secure cookies (Secure · HttpOnly · SameSite)
  • Content Security Policy (nonce-based)
  • Role-based access control (RBAC)
  • Administrative access activity logging
  • Registered in the National PDPL Register
  • Payments via Moyasar (SAMA-licensed, PCI-DSS at provider)
  • Aligned with security best practices
For vulnerability reports or any security matter, the official security contact is it@mahsumaah.sa — our policy is published at /.well-known/security.txt.

The essentials

What we practice today

A quick view of the core controls running behind every project we host.

Hosted inside the Kingdom

All servers run on Huawei Cloud in Riyadh; customer data stays inside Saudi Arabia.

Encryption in transit

HTTPS on every domain with Let's Encrypt certificates issued and renewed automatically; HTTP redirects to HTTPS.

Tenant isolation

Each customer app runs in its own Docker container behind an Nginx reverse proxy, isolated from other tenants.

Network protection

Hardened Linux servers, only required ports exposed, and automatic banning of abusive IPs via fail2ban.

Our own DNS

We run our own authoritative nameservers (ns1/ns2) on BIND9 — no third party controls your zones.

Backups on managed hosting

Real daily per-site backups on managed cPanel/WordPress hosting so data can be restored; backups for PaaS/Docker apps are rolling out.

Monitoring & uptime

Uptime checks every five minutes with ops alerting, plus a public status page.

Access control & audit

Role-based staff access with server-side checks and an append-only audit log; each customer sees only their own data.

Payments via Moyasar

Card payments are handled by Moyasar, a licensed Saudi payment gateway; we do not store raw card data.

Data residency & sovereignty

We host everything on Huawei Cloud ECS instances within the Riyadh region in Saudi Arabia. Customer data and sites are stored and processed inside the Kingdom, and we do not move them to other regions.

We also run our own authoritative nameservers, so control over your domains stays within our infrastructure rather than depending on an external DNS provider.

Encryption & network security

Every domain is served over HTTPS. Let's Encrypt certificates are issued and auto-renewed via certbot per domain, and HTTP requests are redirected to HTTPS automatically.

Our servers run hardened Linux: only the ports required for operation are exposed, and fail2ban bans IP addresses that show abusive behaviour or brute-force attempts.

Tenant isolation & infrastructure

Each customer app runs inside its own Docker container behind an Nginx reverse proxy that routes requests to the correct container. This separates tenants from one another at the process and filesystem level.

We keep the stack simple and understandable — well-known standard components rather than complex machinery — which makes it easier to audit and maintain.

Access control, accounts & audit

Staff access is role-based (Owner, Admin, Support, Engineer) with server-side permission checks on every sensitive action, plus an append-only audit log that records administrative actions.

Customer accounts are isolated, and a customer sees only their own data. SMS-based two-factor authentication is available on accounts that have a phone number — we offer it as an option and do not force it everywhere.

Backups & recovery

We run real daily per-site backups on managed cPanel/WordPress hosting so data can be restored if something goes wrong; per-site backups for PaaS/Docker apps are rolling out. The backup scope and retention period are described in our Service Level Agreement.

We also recommend that customers keep an independent copy of their critical data as an extra precaution.

Monitoring & availability

We monitor platform availability automatically every five minutes, and the ops team is alerted when an issue is detected. You can follow the live status on our status page.

We handle incidents transparently and keep you informed when your service is affected.

Payments & data handling

Card payments are processed through Moyasar, a licensed Saudi payment gateway. Mahsumah Cloud does not store raw card data on its servers. We issue tax invoices compliant with ZATCA requirements.

When you connect GitHub to deploy a project, we request the minimum scopes needed, and we access a repository only when you select it for deployment. For more on how we handle data, see our Privacy Policy.

Responsible disclosure

If you discover a security vulnerability or potential issue, we welcome a report at it@mahsumaah.sa (cc: info@mahsumaah.sa). Describe the steps to reproduce it, and we will review the report and get back to you.

We ask that you avoid accessing other customers' data or disrupting the service while researching, and that you give us reasonable time to address the issue before any public disclosure.

Compliance & documentation

We comply with the applicable regulations in Saudi Arabia and follow conventional operating practices for hosting and data protection. We prefer clarity over overstatement: this page describes what we actually do.

We do not claim on this page any official certifications, licenses, or accreditations that we do not hold.

If you need compliance documentation or further detail about our security controls for a contractual or regulatory purpose, contact us and we will help with what we have. You can also review our Privacy Policy, SLA, and documentation.

Ready to move to Saudi-hosted, managed infrastructure?

Start in minutes, or let our team migrate your current platform for you.