Skip to main content
Architecture & Protection

Security at Aarozi

Our verified technical controls, infrastructure practices, and tenant isolation safeguards

1. Strict Multi-Tenant Isolation

Aarozi is architected so that Business A can never query, view, or modify the customers, visits, or settings of Business B.

  • Row-Level Identity Binding: Every CRM entity (customer, scan, visit, reward, feedback, offer) contains a non-nullable tenant_id foreign key constraint.
  • Authorization Interceptor: Backend route handlers enforce session resolution and reject requests lacking validated tenant ownership (requireBusinessUser).

2. Encryption in Transit & at Rest

  • Transit: All communication between browsers, QR scanners, and Aarozi APIs is forced through TLS 1.3 / HTTPS. Unencrypted HTTP traffic is rejected.
  • At Rest: PostgreSQL database instances use AES-256 block-level encryption for storage volumes and automated continuous backups.

3. Authentication & Password Security

  • Passwords are cryptographically hashed using salted Blowfish/Argon2. Raw passwords are never visible or stored.
  • Sessions are authenticated via signed, scoped tokens with explicit expiration intervals.
  • Email confirmation is required before merchant workspaces can access live customer data.

4. Payment Processing Security

Aarozi does not process or retain raw credit card numbers, CVVs, or bank account credentials. All billing subscriptions are powered directly by Razorpay, a PCI-DSS Level 1 compliant payment provider. Inbound webhook events are verified using cryptographic SHA-256 HMAC signatures with timing-safe comparison to prevent replay attacks.

5. Rate Limiting & Scan Deduplication

Public endpoints (including QR redirects, feedback submission, and enrollment) implement memory-based rate limiting to protect merchant portals against brute-force harvesting, bot scans, and denial-of-service abuse.

6. Reporting Security Issues

We welcome vulnerability reports from independent researchers. Please review our Responsible Disclosure Policy or email our engineering team directly at security@aarozi.com.