Saltar al contenido
سافرSAAFER — Página de inicio

Esta página está disponible en árabe y en inglés.

Trust Center

What we do today to protect the site and the data of those who visit it, in words we can prove. We hold no security certification and call no system unhackable; what we have not done yet is listed below.

Security

  • The site is served over an encrypted connection (TLS) with browser security headers: no embedding in other sites, no content-type sniffing, a restricted referrer policy, restricted browser permissions, and encrypted connections enforced.
  • Visitors have no accounts on the site today except the optional market-alerts account; no card data and no travel documents are stored.
  • The Guide (the chat) runs within limits: a bounded message size, a per-visitor and per-day reply ceiling, a reply timeout, and a server-side kill switch.
  • The interactive demo keeps demo records only, in a demo database; no action reaches a bank, a card network or a real provider.
  • We review and update dependencies when security advisories are published, and keep the number of libraries small.
  • Every release keeps a previous copy on the server to roll back to, and the package is integrity-checked before it runs.

Privacy

  • We count visits without cookies and without keeping IP addresses, under a code that changes every day and is deleted after 400 days (details on the legal information page).
  • The Guide does not store conversations; your messages go to Anthropic’s Claude to write each reply, and we log only anonymous usage data (time, language, page, token counts). Do not put personal data in the chat.
  • The contact form keeps what you send (name, email, message, enquiry type, and organisation and phone if given) on our server so the team can reply and follow up; the message is delivered to the team’s mailbox, new messages are listed in the team’s internal statistics report, and nothing is used for marketing.
  • The market-alerts account keeps your session in a cookie for fourteen days on your device and uses it for nothing else.
  • We use no third-party trackers and no ad networks; fonts are served from our own server.

Data principles

  • We collect the minimum, and ask for nothing the current step does not need.
  • Sensitive documents (passports, IDs, visas, payment details) are not collected on the site today; when they enter the product they will be encrypted, with restricted and logged access, short retention and automatic expiry, and they will never appear in a demo.
  • Every figure and every external fact on the site carries its source and the time it was observed; what has no source is not shown.
  • Payments, when they start, run through licensed providers with hosted or tokenised mechanisms; we store no raw card data, and the user sees who receives each part of an amount.

Principles for institutional environments (none exists today)

  • Each institution isolated in its own environment (a separate database or schema), with its own encryption context and an agreed storage and backup location.
  • Dedicated audit logs, roles agreed in writing (controller/processor), retention and deletion per contract, and no cross-border transfer without agreement.
  • Institutional data never mixes with the market or demo databases.
  • The competent authority or official system is always the system of record; SAAFER is a layer of engagement, orchestration and authorised integration, never a replacement for any authority.

Responsible disclosure

  • If you find a vulnerability in the site, write to us before publishing it and give us reasonable time to fix it; we will not pursue anyone who reports in good faith within these limits.
  • Do not test a vulnerability against other people’s data, do not disrupt the service, and do not keep what you reached.
  • We acknowledge receipt, and we tell you when the vulnerability is fixed.

Not done yet

  • The Content Security Policy runs in report-only mode; not enforced yet.
  • Encrypting stored form submissions at rest (today they are not encrypted at file level).
  • A written retention schedule for contact-form messages; until it exists, messages are deleted on request.
  • A public status page for service availability.
  • A dedicated security-disclosure mailbox; until then, the published technology mailbox is used.
  • Any security certification: we hold no ISO, PCI or SOC certification today, and we say nothing else.

Security contact

To report a vulnerability or ask about data protection, write to the technology team directly or through the contact form.

This page was last reviewed on 3 October 2026