البنية الأمنيةSecurity Architecture

الأمانSecurityفي الصميمby structure

الأمان في ستافلي قيدٌ بنيوي لا طبقةٌ إضافية، فلا يوجد مسارٌ تقني يسمح ببيانات مستأجرٍ بالوصول إلى آخر.Security in Staffly is a structural constraint, not an add-on — no technical path lets one tenant reach another.

لا يوجد مسارٌ تقني يصل ببيانات مستأجر A إلى مستأجر B.There is no technical path from tenant A’s data to tenant B.

ع

عزل البيانات والصلاحياتIsolation & permissions

كل مستأجر يعمل في نطاقٍ مستقل تماماً، والصلاحيات مركّبة ومحدّدة صراحةً.Each tenant runs in a fully independent scope; permissions are composite and explicit.

I.

عزلٌ تامFull isolation

مجموعات Firestore منفصلة، وقواعد أمانٍ تمنع أي استعلامٍ عابر للمستأجرين.Separate Firestore collections and rules that block any cross-tenant query.

II.

مصادقة وصلاحياتAuth & access

Firebase Auth مع Custom Claims، وصلاحياتٌ مركّبة: دور + موضع + نطاق منطقة.Firebase Auth with Custom Claims; composite role + position + region scope.

III.

تفويض مدقّقAudited delegation

كل تفويضٍ طبقةٌ مستقلة بنطاقٍ محدود وتاريخ انتهاءٍ إلزامي وسجل تدقيق.Each delegation is a separate layer with limited scope, mandatory expiry, and audit log.

تشفيرٌEncrypted في النقل والتخزينin transit and at rest

حمايةٌ كاملة للبيانات في كل مرحلة، مع فريق أمانٍ مخصّص واستجابةٍ موثّقة للحوادث.Full data protection at every stage, with a dedicated security team and documented incident response.

TLS 1.3 في النقلTLS 1.3 in transitAES-256 للتخزينAES-256 at restGoogle Cloud KMSCloud KMS keysإشعار خلال 72 ساعة72h breach notice
استفسار أمنيSecurity inquiry

تواصل معContact theفريق الأمانsecurity team

security@staffly.ai