Security claims should be specific, inspectable and honest.
This Trust Center separates controls that are implemented today from safeguards that require configuration, ongoing operational evidence or a platform upgrade.
Trust & controls
| Reference | Date | Record | Branch | Amount | Status |
|---|---|---|---|---|---|
| INV-26-0891 | 31 Aug 2026 | Privileged administrator MFA01 | Addis HQ | ETB 126,500 | Paid |
| INV-26-0890 | 30 Aug 2026 | Organization and role boundaries02 | Adama | ETB 89,760 | Approved |
| INV-26-0889 | 29 Aug 2026 | Business and authentication audit trails03 | Hawassa | ETB 45,600 | Partial |
| INV-26-0888 | 28 Aug 2026 | Privileged administrator MFA01 | Addis HQ | ETB 73,200 | Posted |
| INV-26-0887 | 27 Aug 2026 | Organization and role boundaries02 | Mekelle | ETB 18,975 | Review |
What HisabERP protects—and what still depends on configuration.
Each control includes its current state and the evidence or limitation buyers should understand.
Privileged administrator MFA
Owner and administrator mutations require an AAL2 authenticator session before sensitive financial, inventory, payroll, user or security changes are accepted.
Enforced in the application session and PostgreSQL control path.Organization and role boundaries
Workspace access is scoped by organization and role so operational users do not automatically receive administrator-level control.
Production health checks include detection of public tables that are missing row-level security.Business and authentication audit trails
Material financial actions, authentication activity and security alerts can be recorded as organization-scoped audit events.
MFA-verified administrators can export enabled audit streams as spreadsheet-safe CSV evidence.Browser and application security headers
Responses apply a restrictive content security policy, frame protection, MIME-type protection, referrer controls and permissions restrictions.
Security headers are applied centrally by the Next.js request proxy.Sensitive-route rate limiting
Authentication and API routes use fixed-window request limits as a baseline against repeated automated requests.
The current in-memory limiter is a fallback and should be replaced with a shared regional limiter as deployment scale increases.Leaked-password screening
New and reset passwords are screened for predictable patterns and checked through a privacy-preserving breach-prefix lookup.
Only a short hash prefix is sent to the breach lookup service; the password itself is not transmitted.Backup and restore evidence
Administrators can record encrypted backup evidence, checksums, storage references and isolated restore-test results.
Readiness depends on the organization keeping backup evidence current and performing periodic restore tests.Error-monitoring webhook
Structured server errors can be logged by the hosting platform and forwarded to an external monitoring endpoint.
External forwarding requires the monitoring webhook environment variable to be configured.Point-in-time recovery
Point-in-time recovery is intentionally not presented as active until the connected database plan confirms the capability.
The production controls page keeps this state visible rather than marking an unavailable safeguard as ready.Strong software still requires disciplined administration.
HisabTech maintains product controls. Each organization remains responsible for how users, credentials, exports, devices and operational evidence are managed.
- Maintain application access controls and secure-by-default product behavior.
- Apply security headers and protect sensitive authentication and API routes.
- Provide administrator MFA, audit evidence, alerts and production-control workflows.
- Communicate configuration requirements and avoid presenting planned controls as active.
- Assign the minimum required role to each user and remove access when responsibilities change.
- Require administrators to complete MFA and protect recovery methods.
- Review alerts, audit activity, backup evidence and restore-test status regularly.
- Protect exported data, devices, passwords and third-party integration credentials.
Controls are useful only when their evidence stays current.
The internal production-control workspace tracks administrator MFA, alerts, audit activity, backup evidence, restore testing, database health and monitoring configuration.
Found a security concern?
Provide the affected route, observed behavior, reproduction steps and any relevant timestamps. Do not include customer passwords or unnecessary personal data.