TechnoMindsSaudi digital infrastructure

Security and trust · reviewed 10 August 2026

Trust starts with an exact evidence boundary.

This page separates controls verified in code or exercises from controls that are implemented but not production-proven, and from claims TechnoMinds does not make.

Verified

Controls with current implementation or exercise evidence.

Verified does not mean certified. It identifies a concrete implementation, automated test, or recorded technical exercise.

Verified evidence

Organization and tenant authorization

Customer API access is scoped through authenticated organization, resource, environment, and credential context. Cross-tenant denial is covered by application and database-backed tests.

Verified evidence

Scoped, revocable developer keys

Developer keys carry explicit scopes and environment context. Complete key material is revealed once; stored verification material is not the original plaintext key.

Verified evidence

Sandbox and production separation

The self-service Fatoorah sandbox identifies provider_mode as technominds_synthetic and production_access as false. Sandbox signup does not enable external production traffic.

Verified evidence

Audit and request evidence

Mutating operations emit audit evidence, while customer requests retain correlation, organization, resource, operation, state, and usage context for inspection and support.

Verified evidence

Sensitive logging controls

Application logging redacts authorization and cookie headers. Permanent developer credentials are not intended for browser runtime or customer support payloads.

Verified evidence

PostgreSQL backup and restore mechanism

On 21 July 2026, a real pg_dump and pg_restore cycle was verified into a second database on the same host, including row-count and checksum checks across 126 tables. This proves the mechanism—not independent-region recovery.

Implemented or designed · not production-proven

The boundary still matters.

  • Structured health, request, provider, webhook, provisioning, metering, and unknown-outcome signals exist in the platform design and test surfaces; this page does not assert a public production uptime record or SLA.
  • Provider credential records use opaque secret references and environment metadata; a full external vault recovery exercise has not been performed.
  • Backup and restore scripts are reproducible, but an automated production backup schedule, off-host retention target, point-in-time recovery, and isolated-environment restore remain outstanding.
  • Rollback and recovery procedures are documented, but a complete multi-service disaster-recovery rebuild in an independent environment has not been performed.

Not claimed

No badge by implication.

  • SOC 2, ISO 27001, penetration-test, or independent security-audit completion.
  • ZATCA or SPL approval, certification, qualification, or official-provider status.
  • A verified public production uptime percentage, production SLA, or zero-incident history.
  • Guaranteed regulatory acceptance, zero invoice rejection, or guaranteed carrier acceptance.

Procurement and engineering review

Ask for the evidence your decision requires.

Share the control, data, retention, tenancy, recovery, or production-eligibility requirement. TechnoMinds will identify what is verified, what remains conditional, and what is not currently available.

Contact TechnoMinds