البنية الأمنيةSecurity Architecture

الأمانSecurityفي الصميمby structure

الأمان في ستافلي قيدٌ بنيوي لا طبقةٌ إضافية، فلا يوجد مسارٌ تقني يسمح لبيانات منشأةٍ بالوصول إلى أخرى.Security in Staffly is a structural constraint, not an add-on — no technical path lets one tenant reach another.

لا يوجد مسارٌ تقني يصل ببيانات منشأة A إلى منشأة B.There is no technical path from tenant A’s data to tenant B.

ع

عزل البيانات والصلاحياتIsolation & permissions

كل منشأة يعمل في نطاقٍ مستقل تمامًا، والصلاحيات مركّبة ومحدّدة صراحةً.Each tenant runs in a fully independent scope; permissions are composite and explicit.

I.

عزلٌ تامFull isolation

مجموعات Firestore منفصلة، وقواعد أمانٍ تمنع أي استعلامٍ عابر للمنشآت.Separate Firestore collections and rules that block any cross-tenant query.

II.

مصادقة وصلاحياتAuth & access

Firebase Auth مع Custom Claims، وصلاحياتٌ مركّبة: دور + موضع + نطاق منطقة.Firebase Auth with Custom Claims; composite role + position + region scope.

III.

تفويض مدقّقAudited delegation

كل تفويضٍ طبقةٌ مستقلة بنطاقٍ محدود وتاريخ انتهاءٍ إلزامي وسجل تدقيق.Each delegation is a separate layer with limited scope, mandatory expiry, and audit log.

تشفيرٌEncrypted في النقل والتخزينin transit and at rest

حمايةٌ كاملة للبيانات في كل مرحلة، مع فريق أمانٍ مخصّص واستجابةٍ موثّقة للحوادث.Full data protection at every stage, with a dedicated security team and documented incident response.

TLS 1.3 في النقلTLS 1.3 in transitAES-256 للتخزينAES-256 at restGoogle Cloud KMSCloud KMS keysإشعار خلال 72 ساعة72h breach notice
استفسار أمنيSecurity inquiry

تواصل معContact theفريق الأمانsecurity team

security@staffly.sa