Skip to content

Trust Center

Security answersbefore the first call

Data protection, infrastructure, certifications, residency, and responsible disclosure. The evidence procurement and security teams need before the first call.

5 topics documented

Trust topics

What evaluators ask before they book a meeting

Clear answers to the procurement and security questions enterprise and government buyers ask most.

Data protection

All client data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access follows the principle of least privilege — every engineer works in an isolated environment scoped to the engagement.

Production access requests are logged, reviewed quarterly, and revoked immediately on off-boarding. Security reviews are part of every delivery milestone, not an afterthought.

Infrastructure security

Production environments are deployed on hardened cloud infrastructure with network segmentation, WAF rules, and automated vulnerability scanning on every release.

Patch management follows a defined SLA: critical CVEs within 24 hours, high-severity within one week. Backup policies and disaster-recovery runbooks are tested annually and available to enterprise clients on request.

Certifications & compliance

Our delivery practices align with ISO 27001 principles and OWASP Top 10 guidance. We support clients with NCA (Saudi), NTRA (Egypt), and TDRA (UAE) compliance requirements as part of scoped engagements.

Formal certification documentation and security questionnaire responses are available under NDA for active procurement evaluations. Contact us with your evaluation pack and we will route it to the right team.

Data residency

Workloads can be confined to Egypt (Cairo region) or UAE (Abu Dhabi / Dubai) when contracts require local data hosting. We document data location, storage tier, and all subprocessors before go-live.

Cross-border transfers are subject to written agreement. No client data is processed outside the agreed regions without explicit approval.

Responsible disclosure

We welcome security reports from researchers and clients. Submit findings to security@webenia.com with a description of the vulnerability, reproduction steps, and potential impact. We will acknowledge within two business days.

We follow coordinated disclosure: we agree on a remediation timeline before any public disclosure, and we credit researchers who report valid findings (unless they prefer anonymity).

Need a security questionnaire answered?

Share your evaluation pack. We'll route it to the right team and respond with documented evidence.