Daftari.ma

Security & compliance

Security and data protection

Here is, concretely, how your data is protected on Daftari — without overselling what we are not.

Encryption in transit

Every connection to Daftari, on the website and inside the app, runs over HTTPS with TLS encryption. No data travels unencrypted over the network.

Per-tenant data isolation

Each account is fully partitioned: one company's invoices, clients and documents are never visible from another account.

Role-based permissions

Access to modules and sensitive actions is controlled by a roles-and-permissions system: an accountant, a salesperson and an administrator do not have the same rights.

Tamper-evident audit log

Sensitive actions — creating, editing or deleting invoices, accessing personal data — are recorded in an audit log where each entry is hash-chained to the previous one, so later tampering can be detected.

Blind-indexed personal data

Sensitive personal fields are searchable through a blind index: a one-way keyed hash is stored instead of the plaintext value, so it cannot be decrypted or reversed back to the original, limiting what a breach could expose.

CNDP register and data-subject rights

Daftari keeps a processing register aligned with Law 09-08, runs impact assessments (DPIA) on sensitive processing, and handles access, correction and deletion requests from data subjects.

Nightly backups

The database is backed up every night, with off-site retention, to limit data loss in the event of an incident.

Incident-response procedure

A documented procedure covers detection, triage, notification and remediation for any security incident affecting your data.

What we do not claim

Daftari holds no international security certification (ISO- or SOC-type), is not certified by the CNDP, and is not accredited by the DGI. Our standing with the CNDP is a processing declaration, not a certification or an official accreditation — no Moroccan body has validated the platform to date.