Security & compliance
Security and data protection
Here is, concretely, how your data is protected on Daftari — without overselling what we are not.
Encryption in transit
Every connection to Daftari, on the website and inside the app, runs over HTTPS with TLS encryption. No data travels unencrypted over the network.
Per-tenant data isolation
Each account is fully partitioned: one company's invoices, clients and documents are never visible from another account.
Role-based permissions
Access to modules and sensitive actions is controlled by a roles-and-permissions system: an accountant, a salesperson and an administrator do not have the same rights.
Tamper-evident audit log
Sensitive actions — creating, editing or deleting invoices, accessing personal data — are recorded in an audit log where each entry is hash-chained to the previous one, so later tampering can be detected.
Blind-indexed personal data
Sensitive personal fields are searchable through a blind index: a one-way keyed hash is stored instead of the plaintext value, so it cannot be decrypted or reversed back to the original, limiting what a breach could expose.
CNDP register and data-subject rights
Daftari keeps a processing register aligned with Law 09-08, runs impact assessments (DPIA) on sensitive processing, and handles access, correction and deletion requests from data subjects.
Nightly backups
The database is backed up every night, with off-site retention, to limit data loss in the event of an incident.
Incident-response procedure
A documented procedure covers detection, triage, notification and remediation for any security incident affecting your data.
What we do not claim
Daftari holds no international security certification (ISO- or SOC-type), is not certified by the CNDP, and is not accredited by the DGI. Our standing with the CNDP is a processing declaration, not a certification or an official accreditation — no Moroccan body has validated the platform to date.