Security
Wallet data sits at the centre of your business.
Here is how we hold it.
Encryption-at-rest. Tokenised PAN storage. Single-tenant database per operator on Enterprise. Sub-processor disclosure on this page, updated when it changes. Disclosure address below.
01 · Encryption
Data at rest, data in transit.
At rest
Database storage is encrypted with AES-256-GCM via the cloud provider's managed key service. Customer PII fields (phone, name, address) are additionally encrypted at the application layer with per-tenant data keys, derived from envelope encryption against a hardware-backed root key. Backups inherit the at-rest encryption posture.
In transit
All external traffic terminates at TLS 1.3 with modern cipher suites (TLS_AES_256_GCM_SHA384 preferred). HSTS preload is shipped. Internal service-to-service traffic uses mutual TLS with short-lived workload identities. The operator dashboard ships strict-transport-security, content-security-policy, x-content-type-options: nosniff, and referrer-policy: strict-origin-when-cross-origin by default.
Cardholder data
Feddi does not store raw PANs. Card details flow directly to the acquirer's tokenisation endpoint; we hold only the resulting network token plus brand + last-four for display. PCI DSS scope is minimised to the operator-dashboard browser + acquirer-redirect surfaces.
02 · Access control
Who can read what, and how we know.
Operator dashboard
Role-based access with three default roles (Owner, Operator, Read-only) plus custom roles on Enterprise. Single sign-on via SAML 2.0 + SCIM provisioning on Operator and Enterprise tiers. Hardware-token-backed MFA enforceable per role. Per-branch scoping limits operators to the data and surfaces for their branches.
Audit log
Every read of customer-level data and every write that creates or modifies a wallet, customer record, or incentive rule emits a structured audit event. Logs include actor, source IP, action, target IDs, and outcome. Audit log is append-only, exportable to the operator's SIEM via webhook or scheduled export.
Internal access
Feddi engineering does not access operator customer data as a default. Production access requires explicit JIT escalation through a change ticket, two-engineer review, and is automatically logged. Background workers run with workload identities scoped to the minimum required dataset.
03 · Compliance posture
Where we are with attestations.
- PCI DSS Scope minimised, controls implemented Certification level pending; see acquirer integration scope.
- SOC 2 Type II Audit in progress Auditor and audit-window dates available under NDA on request.
- KSA PDPL Implemented Data subject rights, retention windows, cross-border transfer controls per the Personal Data Protection Law (KSA, 2023).
- GDPR Implemented DSR processing, lawful basis surfacing, processor agreements for sub-processors. DPO contact on this page.
- ISO 27001 On roadmap Scoped for the year following SOC 2 closure.
Every status above reflects where we are today. We will not claim a certification we do not hold. When status changes, this page changes the same day.
04 · Sub-processors
Every third party that touches operator data.
| Sub-processor | Purpose | Data scope | Region |
|---|---|---|---|
| Amazon Web Services | Core compute, storage, networking | All operator data | me-central-1 (UAE), me-south-1 (Bahrain) |
| Cloudflare | Edge, DNS, DDoS, WAF | Request metadata, no customer payload | Global edge, KSA + UAE PoPs primary |
| Stripe / acquirer-of-record | Card tokenisation, wallet top-up rails | Card BIN + last4, network token | Per acquirer agreement |
| Resend | Transactional email (receipts, password resets) | Email + transactional context | EU + US data centres |
| Twilio (Programmable Messaging) | SMS receipts, wallet pass install links | Phone + message body | Per Twilio region; GCC routing via local carriers |
| Sentry | Application error monitoring | Stack traces, scrubbed of PII | EU data centre |
Operators on Enterprise can request data-residency commitments and sub-processor opt-out for specific surfaces. Notice of any change to this list ships 30 days before activation by default; faster notice is configurable per agreement.
05 · Disclosure
Found something. Tell us.
If you believe you have found a security vulnerability affecting Feddi, report it to security@feddi.com. We acknowledge reports within one business day. We do not pursue legal action against good-faith researchers acting under standard responsible-disclosure expectations.
In scope
- feddi.com and all subdomains we operate
- The operator dashboard at app.feddi.com
- Public APIs documented at docs.feddi.com
- Wallet pass surfaces in Apple Wallet and Google Wallet
Out of scope
- Findings requiring physical access to operator devices
- Social-engineering of Feddi staff or operator employees
- Denial-of-service findings that depend on traffic volume rather than a logic flaw
- Third-party services not operated by Feddi (sub-processor surfaces, report to the sub-processor)
A formal bug bounty programme is on the roadmap. Until it ships we coordinate disclosure case-by-case with a thank-you and a public acknowledgement (with your consent) once the fix is live.
Built for the future. Available today.
A deeper security review packet is available under NDA. Ask for it from your sales contact.