Trust
Data Security
Last updated: August 23, 2026
NaddaraOS uses tenant-scoped access controls, encrypted transport, server-side authentication, audit events, rate limits, and database isolation controls to protect the platform.
Access protection
Application sessions use Secure, HttpOnly cookies with short-lived access credentials and rotating refresh-token families. State-changing browser requests are protected by a same-origin CSRF strategy.
Tenant isolation
Tenant resolution, authorization policies, database boundaries, storage access, billing, analytics, and realtime channels are checked against the active tenant context.
Reporting a concern
Report a suspected security issue privately to [email protected]. Do not include passwords, access tokens, refresh tokens, or customer records in a report.