Skip to content
toDubai

Security

Last updated 18 August 2026

You would be handing over your entire request pipeline, your clients' identity documents and your financial records. This page sets out what protects them, and is deliberately specific rather than reassuring.


Access control

  • Nine staff roles covering sales, coordination, operations, finance, supervision and administration, plus stackable workflow roles for people who genuinely do two jobs.
  • Partner scoping. A partner agency signing into the portal or the mobile app sees only their own clients. There is no view that exposes another partner's book.
  • Client scoping. A client sees only their own companies, applications and requests.

Data isolation

The platform is multi-tenant and runs branded instances for multiple licensing companies. Isolation between organisations is enforced at the data layer rather than by hiding things in the interface, which is the distinction that matters when someone changes a URL by hand.

Audit trails

Every action on an application is recorded with the person who performed it, the role they held at the time, and when. This is what makes a five-week application explainable afterwards, and it is also what makes a disputed approval a matter of record rather than recollection. There is a global cross-system activity feed for administrators.

Internal notes never reach clients

Notes are split into internal and client-visible as separate fields with separate rules. Visibility is fail-closed: anything not explicitly marked client-visible is treated as internal. Your operations team can write what they actually think without the risk of it surfacing on a client's screen.

Documents and storage

  • Uploaded documents are held in encrypted cloud object storage, attached to the record they belong to.
  • Data is encrypted in transit and at rest.
  • Public progress trackers use secure tokenised links, so a client can check their application without an account and without that link exposing anything else.

Application and API protection

  • Rate limiting on API endpoints.
  • Request sanitisation on inbound data.
  • API traffic logging for investigation and abuse detection.
  • Inbound webhooks only, so there are no public API keys to leak.

Financial controls

Payments and expenses require finance approval before they count, with a bulk approval queue and an audit record of each decision. A pricing guardrail blocks invoices priced 30% or more below list, which is a control against both error and internal fraud.

Certifications

We do not hold ISO 27001 or SOC 2 certification, and we will not claim otherwise. What we can do is walk your technical or compliance reviewer through the control set above in detail, answer specific questions directly, and put the answers in writing. If a formal certification is a hard requirement for your procurement process, tell us early rather than late.

Reporting a vulnerability

If you believe you have found a security issue, email hello@todubai.ae with the details and give us a reasonable window to fix it before disclosing publicly. We will acknowledge, keep you updated, and credit you if you want the credit.

Related

See also our privacy policy and data processing terms.