Skip to main content
Biloo
HisabERP Trust Center

Security claims should be specific, inspectable and honest.

This Trust Center separates controls that are implemented today from safeguards that require configuration, ongoing operational evidence or a platform upgrade.

b.Biloo ERP
Security operations workspace

Trust & controls

Documented safeguards9Current control register
Implemented5Verified product controls
Needs configuration4Operational or upgrade dependent
ReferenceDateRecordBranchAmountStatus
INV-26-089131 Aug 2026Privileged administrator MFA01Addis HQETB 126,500Paid
INV-26-089030 Aug 2026Organization and role boundaries02AdamaETB 89,760Approved
INV-26-088929 Aug 2026Business and authentication audit trails03HawassaETB 45,600Partial
INV-26-088828 Aug 2026Privileged administrator MFA01Addis HQETB 73,200Posted
INV-26-088727 Aug 2026Organization and role boundaries02MekelleETB 18,975Review
Control register

What HisabERP protects—and what still depends on configuration.

Each control includes its current state and the evidence or limitation buyers should understand.

01Implemented

Privileged administrator MFA

Owner and administrator mutations require an AAL2 authenticator session before sensitive financial, inventory, payroll, user or security changes are accepted.

Enforced in the application session and PostgreSQL control path.
02Implemented

Organization and role boundaries

Workspace access is scoped by organization and role so operational users do not automatically receive administrator-level control.

Production health checks include detection of public tables that are missing row-level security.
03Implemented

Business and authentication audit trails

Material financial actions, authentication activity and security alerts can be recorded as organization-scoped audit events.

MFA-verified administrators can export enabled audit streams as spreadsheet-safe CSV evidence.
04Implemented

Browser and application security headers

Responses apply a restrictive content security policy, frame protection, MIME-type protection, referrer controls and permissions restrictions.

Security headers are applied centrally by the Next.js request proxy.
05Baseline control

Sensitive-route rate limiting

Authentication and API routes use fixed-window request limits as a baseline against repeated automated requests.

The current in-memory limiter is a fallback and should be replaced with a shared regional limiter as deployment scale increases.
06Implemented

Leaked-password screening

New and reset passwords are screened for predictable patterns and checked through a privacy-preserving breach-prefix lookup.

Only a short hash prefix is sent to the breach lookup service; the password itself is not transmitted.
07Operational process

Backup and restore evidence

Administrators can record encrypted backup evidence, checksums, storage references and isolated restore-test results.

Readiness depends on the organization keeping backup evidence current and performing periodic restore tests.
08Configuration-ready

Error-monitoring webhook

Structured server errors can be logged by the hosting platform and forwarded to an external monitoring endpoint.

External forwarding requires the monitoring webhook environment variable to be configured.
09Platform upgrade required

Point-in-time recovery

Point-in-time recovery is intentionally not presented as active until the connected database plan confirms the capability.

The production controls page keeps this state visible rather than marking an unavailable safeguard as ready.
Shared responsibility

Strong software still requires disciplined administration.

HisabTech maintains product controls. Each organization remains responsible for how users, credentials, exports, devices and operational evidence are managed.

HisabTech responsibilities
  • Maintain application access controls and secure-by-default product behavior.
  • Apply security headers and protect sensitive authentication and API routes.
  • Provide administrator MFA, audit evidence, alerts and production-control workflows.
  • Communicate configuration requirements and avoid presenting planned controls as active.
Customer responsibilities
  • Assign the minimum required role to each user and remove access when responsibilities change.
  • Require administrators to complete MFA and protect recovery methods.
  • Review alerts, audit activity, backup evidence and restore-test status regularly.
  • Protect exported data, devices, passwords and third-party integration credentials.
Operational assurance

Controls are useful only when their evidence stays current.

The internal production-control workspace tracks administrator MFA, alerts, audit activity, backup evidence, restore testing, database health and monitoring configuration.

01Protect privileged accessRequire AAL2 MFA before administrators change sensitive records or security policy.
02Review activityInspect authentication, financial and security-alert evidence instead of relying on memory.
03Verify continuityKeep backup evidence current and document isolated restore tests.
04Escalate findingsReport suspected vulnerabilities or security concerns directly to HisabTech.
Responsible security reporting

Found a security concern?

Provide the affected route, observed behavior, reproduction steps and any relevant timestamps. Do not include customer passwords or unnecessary personal data.

Report securely by emailReview integrations