Trust & Security

We treat your data
like it was ours.

Enterprise-grade security practices, transparent subprocessors, and a compliance roadmap you can verify. No vague assurances — specific commitments, in writing.

Security by design

Six commitments we actually enforce.

Encryption everywhere

AES-256 encryption at rest for all stored data. TLS 1.3 for data in transit. Client credentials and API keys are stored in encrypted vaults, never in source code.

No data training

Client data, conversations, and documents are never used to train AI models. Our Claude integration uses the API with zero-retention settings where available.

Background-checked team

Every consultant who may access client systems or data undergoes background verification. Access is granted on a least-privilege basis and reviewed quarterly.

NDA-first engagements

We sign mutual NDAs before any scoping call that could reveal sensitive information. Your IP stays yours — repositories, prompts, and eval suites are handed over cleanly.

Isolated environments

Client instances and data are logically separated. Development, staging, and production environments use distinct credentials and network segmentation.

Audit trail by default

Every action an agent takes is logged. Every configuration change is documented. You get full access to logs, runbooks, and change history from day one.

Compliance roadmap

Where we are, and where we are headed.

In progress

SOC 2 Type II

Target: Q1 2027

Audit scheduled with independent assessor

Planned

ISO 27001

Target: Q3 2027

Framework mapping complete; implementation underway

Active

GDPR compliance

Target: Live

Data processing agreements available on request

Active

Background checks

Target: Live

All client-facing staff verified annually

Certifications

What the team is actually certified in.

ServiceNow certifications are held by individuals, not companies, and they are the one competence signal we can publish without needing a client's permission. So here is what the delivery team holds.

To be precise: these are practitioner certifications held across the team. They are not a ServiceNow partner tier — we are not a ServiceNow partner, and we say so on our about page too. We will tell you who specifically is certified in what, by name, during scoping.

CTA

Certified Technical Architect

ServiceNow's senior architecture credential. Relevant when the question is whether a design will survive three upgrades, not whether a form can be built.

ArchX

Architect-level certification

Architect-track credentials covering platform design, data modelling, and instance strategy across a multi-application estate.

CSA

Certified System Administrator

The platform baseline — administration, configuration, and the upgrade discipline every engagement depends on.

CAD

Certified Application Developer

Scoped application development against supported APIs, which is what keeps a custom app upgradeable.

CIS

Certified Implementation Specialist

Product-specific implementation credentials across the modules we deliver — the certification that maps to a named product rather than to the platform generally.

Micro-certifications

Targeted capability credentials

Narrower ServiceNow credentials for individual capabilities, kept current as the platform releases change.

Middle East

The frameworks your regulator cares about.

SOC 2, ISO 27001 and GDPR above are about us. This list is about you. A Gulf security questionnaire asks a different set of questions from a US or European one, and the honest answer to most of them is architectural rather than a certificate.

To be precise about what this section claims: we design and configure against these control families and give you the mapping in writing. We are not accredited under any of them, and where a framework requires an accredited audit, that audit belongs to you or your assessor. Anyone telling you otherwise is selling you something.

NCA ECC

Saudi Arabia

Essential Cybersecurity Controls, mandatory for government entities and critical national infrastructure. We map platform access control, logging, change management, and third-party access to the relevant control families, and hand over the mapping.

PDPL

Saudi Arabia

Personal Data Protection Law, enforced by SDAIA. Consent, retention, and cross-border transfer are design decisions in any workflow carrying personal data — we settle them before build, not after.

PDPL

UAE

Federal Decree-Law 45/2021. Free-zone entities in DIFC and ADGM operate under their own data protection regimes, so a group spanning both mainland and free zone has more than one to satisfy.

NDMO standards

Saudi Arabia

National Data Management Office standards for classification, quality, and retention. Classification drives platform configuration, so it belongs in the design phase.

SAMA CSF

Saudi Arabia

Saudi Central Bank Cyber Security Framework, applying to banks, insurers, and financing companies. Change management and privileged access are where a workflow platform is most directly in scope.

DESC / TDRA

UAE

Dubai Electronic Security Center requirements for Dubai government entities, alongside federal TDRA regulation. Multi-emirate programmes frequently answer to both.

Subprocessors

Who else touches your data, and why.

We keep this list short and current. If we add a subprocessor that could access client data, we notify affected clients 30 days in advance.

VendorPurposeData involvedLocation
AnthropicClaude API — AI reasoning and agent responsesConversation transcripts, no client PII unless explicitly sharedUS (with zero-retention where available)
VercelStatic site hosting and edge functionsWebsite content, form submissions, analyticsGlobal edge
ServiceNowPlatform implementation and managed servicesPlatform configuration, workflow data, incident recordsClient instance — client-controlled
Incident response

What happens if something goes wrong.

We maintain a written incident response plan reviewed quarterly. Every consultant knows the escalation path.

Detection

Automated monitoring + client reporting channels. PagerDuty for critical alerts.

Notification

Client notified within 24 hours of confirmed incident. Initial assessment within 4 hours for P1.

Resolution & RCA

Fix deployed, then root cause analysis shared within 72 hours with preventive measures.

Security contacts
security@ifbash.com

For security questionnaires, audit requests, and incident reports.

Responsible disclosure

Found a vulnerability? Email security@ifbash.com with details. We respond within 48 hours and credit researchers who report responsibly.

Data residency

Client data stays in the region you specify where technically feasible. ServiceNow instances are region-bound by default.

FAQ

Security questions we hear a lot.

Ask our security team

For ServiceNow work, data lives in your ServiceNow instance — we do not host it. For AI agents we build, conversation data is processed via the Claude API (US-based, with zero-retention settings) and stored only where you explicitly configure retention. Web form data is stored in Vercel edge infrastructure.

Need our security questionnaire?

We share our full security pack — questionnaire, subprocessors list, incident response plan, and compliance roadmap — under NDA within one business day.