Security and privacy

Limited access, traceable changes and tested recovery.

This page describes controls implemented in Menazil. We do not claim external security certifications we have not earned.

Organization data isolation

Database policies separate each organization's data, while permissions are role-scoped and time-aware.

Private guest documents

Guest identity files are stored privately rather than as public links, with access tied to the booking and an authorized role.

Audited operational changes

Booking, payment and access changes are logged. Financial history cannot be silently rewritten by the client interface.

Recovery rehearsal

The delivery pipeline rebuilds a clean database, runs security-boundary regressions and restores an application-schema backup into an isolated database.