Cybersecurity
We build our platform following practices aligned with Kuwait's National Basic Cybersecurity Controls.
Governance
Cybersecurity is an accountable management responsibility, with a named owner for each system and periodic review of access and policies.
Identity and access management
- Least-privilege access for every account.
- Secrets held in a central key vault; no credentials in code or config files.
- Managed identities for service-to-service authentication instead of static credentials.
- Credential rotation whenever exposure is suspected.
Data protection and encryption
- End-to-end HTTPS with encryption enforced on every page.
- Encryption at rest for databases and backups.
- Uploaded files are compressed and stripped of sensitive metadata before publication.
Application security
- Dependencies kept current and disclosed vulnerabilities patched promptly.
- Development separated from production, with all code in version control.
- Authorisation checks on all editorial endpoints.
Backup and continuity
Databases are backed up regularly with point-in-time restore, and published content moves to the archive after two years.
Incident response
We maintain a defined path for classifying and handling incidents and notifying the relevant authorities where required. If you discover a vulnerability, please report it to us privately before disclosing it: info@q8hashtagat.com
Protecting journalistic sources
Source correspondence is treated confidentially and metadata is stripped from incoming images and files — protecting sources is part of our information security.
Note: this page describes our security practices and our alignment with the national controls. It is not a formal certification of compliance; full alignment is subject to review by the competent authorities.
