Security & Trust

Trust is built into the system, not added later.

BASMA OS products are built with clear boundaries between companies, identities and roles. Our goal is to make security controls part of the product architecture itself.

This page describes controls that are actually implemented and claims no certifications we do not hold.

Payments

Your card details never touch our servers.

Online payments for BASMOV, Basma Agency and Basma by Sarah are processed by Stripe. Card details are entered directly into secure payment fields hosted by Stripe, so they never reach our servers and we do not store them.

BASMA OS appears on your card statement, followed by the product you purchased from.

Controls implemented in BASMOV

Protection across multiple layers.

These are examples of controls present in the current application, not a list of future claims.

Company context

Company boundaries are used across operational areas to scope data and actions to the appropriate context.

Role-aware access

The platform treats roles and workspaces as real access boundaries rather than cosmetic interface differences.

Credential protection

Passwords are stored using the application framework’s hashing mechanisms rather than as plaintext credentials.

Login rate limiting

The login flow includes rate limiting against repeated authentication attempts.

Signed URLs

Selected flows use signed and temporary URLs where link integrity needs to be verified.

Webhook verification

Stripe signatures are verified before subscription events are accepted by the webhook endpoint.

Surface separation

The public website is not the application.

basmaos.com introduces the company and its products and holds no customer data. Applications run on their own domains, such as app.basmov.com, with separate access boundaries and sessions.

Transparency

We say what we can support.

Trust does not require claims larger than reality, so we make no claims about certifications or service levels that are not established.

  • No SOC 2 claim
  • No ISO 27001 claim
  • No unverified SLA claim

Report a vulnerability

If you notice a security issue in any of our products, write to us and we will treat it as a priority.