Trust & Security
We treat your data
like it was ours.
Enterprise-grade security practices, transparent subprocessors, and a compliance roadmap you can verify. No vague assurances — specific commitments, in writing.
Six commitments we actually enforce.
Encryption everywhere
AES-256 encryption at rest for all stored data. TLS 1.3 for data in transit. Client credentials and API keys are stored in encrypted vaults, never in source code.
No data training
Client data, conversations, and documents are never used to train AI models. Our Claude integration uses the API with zero-retention settings where available.
Background-checked team
Every consultant who may access client systems or data undergoes background verification. Access is granted on a least-privilege basis and reviewed quarterly.
NDA-first engagements
We sign mutual NDAs before any scoping call that could reveal sensitive information. Your IP stays yours — repositories, prompts, and eval suites are handed over cleanly.
Isolated environments
Client instances and data are logically separated. Development, staging, and production environments use distinct credentials and network segmentation.
Audit trail by default
Every action an agent takes is logged. Every configuration change is documented. You get full access to logs, runbooks, and change history from day one.
Where we are, and where we are headed.
SOC 2 Type II
Target: Q1 2027
Audit scheduled with independent assessor
ISO 27001
Target: Q3 2027
Framework mapping complete; implementation underway
GDPR compliance
Target: Live
Data processing agreements available on request
Background checks
Target: Live
All client-facing staff verified annually
What the team is actually certified in.
ServiceNow certifications are held by individuals, not companies, and they are the one competence signal we can publish without needing a client's permission. So here is what the delivery team holds.
To be precise: these are practitioner certifications held across the team. They are not a ServiceNow partner tier — we are not a ServiceNow partner, and we say so on our about page too. We will tell you who specifically is certified in what, by name, during scoping.
CTA
Certified Technical ArchitectServiceNow's senior architecture credential. Relevant when the question is whether a design will survive three upgrades, not whether a form can be built.
ArchX
Architect-level certificationArchitect-track credentials covering platform design, data modelling, and instance strategy across a multi-application estate.
CSA
Certified System AdministratorThe platform baseline — administration, configuration, and the upgrade discipline every engagement depends on.
CAD
Certified Application DeveloperScoped application development against supported APIs, which is what keeps a custom app upgradeable.
CIS
Certified Implementation SpecialistProduct-specific implementation credentials across the modules we deliver — the certification that maps to a named product rather than to the platform generally.
Micro-certifications
Targeted capability credentialsNarrower ServiceNow credentials for individual capabilities, kept current as the platform releases change.
The frameworks your regulator cares about.
SOC 2, ISO 27001 and GDPR above are about us. This list is about you. A Gulf security questionnaire asks a different set of questions from a US or European one, and the honest answer to most of them is architectural rather than a certificate.
To be precise about what this section claims: we design and configure against these control families and give you the mapping in writing. We are not accredited under any of them, and where a framework requires an accredited audit, that audit belongs to you or your assessor. Anyone telling you otherwise is selling you something.
NCA ECC
Saudi ArabiaEssential Cybersecurity Controls, mandatory for government entities and critical national infrastructure. We map platform access control, logging, change management, and third-party access to the relevant control families, and hand over the mapping.
PDPL
Saudi ArabiaPersonal Data Protection Law, enforced by SDAIA. Consent, retention, and cross-border transfer are design decisions in any workflow carrying personal data — we settle them before build, not after.
PDPL
UAEFederal Decree-Law 45/2021. Free-zone entities in DIFC and ADGM operate under their own data protection regimes, so a group spanning both mainland and free zone has more than one to satisfy.
NDMO standards
Saudi ArabiaNational Data Management Office standards for classification, quality, and retention. Classification drives platform configuration, so it belongs in the design phase.
SAMA CSF
Saudi ArabiaSaudi Central Bank Cyber Security Framework, applying to banks, insurers, and financing companies. Change management and privileged access are where a workflow platform is most directly in scope.
DESC / TDRA
UAEDubai Electronic Security Center requirements for Dubai government entities, alongside federal TDRA regulation. Multi-emirate programmes frequently answer to both.
Who else touches your data, and why.
We keep this list short and current. If we add a subprocessor that could access client data, we notify affected clients 30 days in advance.
| Vendor | Purpose | Data involved | Location |
|---|---|---|---|
| Anthropic | Claude API — AI reasoning and agent responses | Conversation transcripts, no client PII unless explicitly shared | US (with zero-retention where available) |
| Vercel | Static site hosting and edge functions | Website content, form submissions, analytics | Global edge |
| ServiceNow | Platform implementation and managed services | Platform configuration, workflow data, incident records | Client instance — client-controlled |
What happens if something goes wrong.
We maintain a written incident response plan reviewed quarterly. Every consultant knows the escalation path.
Automated monitoring + client reporting channels. PagerDuty for critical alerts.
Client notified within 24 hours of confirmed incident. Initial assessment within 4 hours for P1.
Fix deployed, then root cause analysis shared within 72 hours with preventive measures.
For security questionnaires, audit requests, and incident reports.
Found a vulnerability? Email security@ifbash.com with details. We respond within 48 hours and credit researchers who report responsibly.
Client data stays in the region you specify where technically feasible. ServiceNow instances are region-bound by default.
For ServiceNow work, data lives in your ServiceNow instance — we do not host it. For AI agents we build, conversation data is processed via the Claude API (US-based, with zero-retention settings) and stored only where you explicitly configure retention. Web form data is stored in Vercel edge infrastructure.
Need our security questionnaire?
We share our full security pack — questionnaire, subprocessors list, incident response plan, and compliance roadmap — under NDA within one business day.