Security & Compliance
for demanding institutions.
Harch Atelier is engineered for Morocco's most demanding institutions. End-to-end cryptographic security, local regulatory compliance, complete traceability. Here is how we protect your data — and ours.
Built on cryptographic primitives, not promises.
Every layer of the stack uses verifiable standards. Implementations are audited, and the artifacts (audit trail, keys, logs) are immutable.
ZKP Authentication
Zero-Knowledge Proof: your password never leaves your browser.
Your password is hashed client-side (SRP-6a + Argon2id). The server never receives the secret in cleartext and cannot reconstruct it.
WebAuthn / Passkeys
TouchID, FaceID, YubiKey. Native FIDO2 support.
Passwordless authentication built on the W3C WebAuthn + CTAP2 standards. Each device generates a unique key pair per domain.
SHA-256 Audit Trail
Every admin action is hashed and chained. Tamper detection.
Every audit entry contains hash(nonce + previous_hash + action + user + ts). Modifying any entry breaks the chain and is detected immediately.
Session Revocation
sessionVersion bump. JWT invalidated instantly.
Every user has a server-side sessionVersion counter. Every signed JWT carries this number; bumping the counter → all existing tokens are rejected on the next request.
Moroccan regulatory framework, verifiable traceability.
We operate under the Moroccan legal framework (CNDP, Loi 09-08) with a sovereign in-Morocco hosting option for institutions that require it.
Five binding commitments on your data.
These principles are written into our DPAs and verifiable via the audit trail.
Encryption in transit
TLS 1.3 on every connection. Modern cipher suites (ChaCha20-Poly1305, AES-GCM). HSTS preload, ECDSA certificates with automated 90-day rotation.
Encryption at rest
PostgreSQL AES-256 (pgcrypto + TDE). Encrypted backups with a dedicated KMS. Keys rotated quarterly, with role separation (KMS admin ≠ DBA).
Multi-tenant isolation
Every company's data is isolated by tenant_id + PostgreSQL Row-Level Security. No cross-tenant query is possible, even in the event of an application bug.
No data resale
Your data is never sold to third parties. No sharing with advertising networks. No model training on your data without explicit written consent.
Export/deletion on request
GDPR-compatible. Full export (JSON + PDF) within 30 days. Verified deletion (audit trail + KMS purge) within 30 days. Right to be forgotten, guaranteed.
Role hierarchy, granular permissions.
Every user is assigned a role with a numeric access level. Permissions are cumulative and verifiable via the audit trail.
RBAC is enforced at the middleware + database layer (Row-Level Security). Every role change is logged in the audit trail with a chaining hash.
From detection to post-mortem, in under 14 days.
A formalized procedure, tested quarterly. Client notification within 72h in line with CNDP requirements.
The Sentinel cron detects the anomaly. Pattern matching on logs, sentiment alerts, and API activity spikes.
WhatsApp + email + dashboard. The on-call team and the security lead are notified simultaneously.
DEFCON 1 → Comms Director notified. War room activated, impacted systems isolated.
Full report + audit trail. Root-cause analysis, corrective measures, client communication.
Every admin action, cryptographically chained.
A real excerpt from the audit trail (anonymized). Each entry contains the hash of the previous one — any tampering breaks the chain immediately.
The hashes above are truncated to 16 characters for demonstration. In production: full SHA-256 (64 hex characters), chained in real time.
Need a dedicated security review?
For Sovereign and Enterprise accounts, we provide a tailored security dossier: DPA, sub-processors, processing register, certificates, audit reports.