Home About Us Features Solutions by Industry Pricing Contact Us
EN AR DE
Login

INFORMATION SECURITY POLICY

Esyana Field Maintenance Management Platform

Document Version: 1.0
Effective Date: 26 July 2026
Last Updated: 26 July 2026

INFORMATION SECURITY POLICY

This Information Security Policy ("Policy") defines the security principles, controls, responsibilities, and procedures used by Sadeid to protect information processed through the Esyana Field Maintenance Management Platform ("Esyana", "Platform", "Service").

Sadeid is registered in the Hashemite Kingdom of Jordan under Registration Number 1210822026.

This Policy applies to:

  • Esyana software systems

  • Cloud infrastructure

  • Databases

  • Applications

  • APIs

  • Customer data

  • Internal systems

  • Employees

  • Contractors

  • Service providers

1. Purpose

The purpose of this Policy is to establish a framework to:

  • Protect confidentiality of customer information.

  • Maintain integrity of business data.

  • Ensure availability of the Esyana platform.

  • Prevent unauthorized access.

  • Reduce cybersecurity risks.

  • Establish security responsibilities.

  • Support compliance with applicable laws and contractual obligations.

2. Security Principles

Sadeid follows these core security principles:

Confidentiality

Information is accessible only to authorized users.

Integrity

Information must remain accurate and protected against unauthorized modification.

Availability

The Platform should remain accessible and operational for customers.

Least Privilege

Users and employees receive only the access required to perform their responsibilities.

Defense in Depth

Multiple layers of security controls are used to reduce risk.

3. Scope of Protected Information

Information protected under this Policy includes:

Customer Data

  • Client information

  • Asset records

  • Device information

  • Work orders

  • Maintenance history

  • Reports

  • Photos

  • Documents

  • Invoices

  • Inventory information

  • Warranty information

Personal Information

  • User names

  • Email addresses

  • Phone numbers

  • Employee information

  • Technician information

  • Login information

Company Information

  • Source code

  • Technical documentation

  • Infrastructure details

  • Business information

  • Internal procedures

4. Information Security Responsibilities

Sadeid Responsibilities

Sadeid is responsible for:

  • Maintaining security controls.

  • Protecting customer data.

  • Monitoring infrastructure.

  • Managing vulnerabilities.

  • Responding to security incidents.

  • Training authorized personnel.

  • Improving security practices.

Customer Responsibilities

Customers are responsible for:

  • Protecting account credentials.

  • Managing user permissions.

  • Training their employees.

  • Reviewing access rights.

  • Protecting their own devices.

  • Reporting suspected security issues.

5. Access Control Policy

Sadeid implements access control measures designed to prevent unauthorized access.

Controls include:

  • Unique user accounts.

  • Role-Based Access Control (RBAC).

  • Permission management.

  • Administrative access restrictions.

  • User activity logging.

  • Account deactivation procedures.

6. Role-Based Access Control

Esyana uses permission-based access management.

Customers can configure access according to roles such as:

  • Super Administrator

  • Company Administrator

  • Service Manager

  • Maintenance Supervisor

  • Technician

  • Warehouse Manager

  • Accountant

  • Client Portal User

  • Read-Only User

Each role should have only the permissions necessary for its function.

7. Authentication Security

Sadeid implements authentication controls including:

  • Secure password storage.

  • Password complexity requirements.

  • Session management.

  • Login monitoring.

  • Account lockout mechanisms where appropriate.

Recommended additional controls:

  • Multi-factor authentication (MFA).

  • Single Sign-On (SSO) for enterprise customers.

8. Password Policy

Users should:

  • Use strong passwords.

  • Avoid password reuse.

  • Keep passwords confidential.

  • Change passwords when compromise is suspected.

Passwords must never be:

  • Stored in plain text.

  • Shared between users.

  • Sent through unsecured communication channels.

9. Data Encryption

Sadeid uses encryption technologies designed to protect information.

Data in Transit

Communication between users and Esyana systems should be protected using secure protocols such as:

  • HTTPS

  • TLS encryption

Data at Rest

Where applicable, stored information should be protected using encryption mechanisms provided by the infrastructure environment.

Examples:

  • Databases

  • Backups

  • Storage systems

10. Application Security

Sadeid follows secure software development practices.

Security practices include:

  • Secure coding standards.

  • Code reviews.

  • Dependency monitoring.

  • Input validation.

  • Authentication checks.

  • Authorization checks.

  • Error handling.

  • Security testing before major releases.

11. Secure Development Lifecycle (SSDLC)

Software development activities should include:

Planning

  • Identify security requirements.

  • Assess risks.

Development

  • Follow secure coding practices.

  • Avoid insecure libraries.

  • Review sensitive functionality.

Testing

Testing may include:

  • Functional testing.

  • Security testing.

  • Vulnerability scanning.

  • Penetration testing.

Deployment

  • Secure configuration.

  • Controlled releases.

  • Monitoring after deployment.

12. Vulnerability Management

Sadeid maintains procedures to identify and address security weaknesses.

Activities may include:

  • Security updates.

  • Dependency monitoring.

  • Vulnerability assessments.

  • Infrastructure reviews.

  • Security testing.

Critical vulnerabilities should receive priority remediation.

13. Network Security

Security controls may include:

  • Firewalls.

  • Network segmentation.

  • Access restrictions.

  • Secure communication protocols.

  • Monitoring systems.

Administrative access to production systems should be restricted to authorized personnel.

14. Database Security

Database security controls include:

  • Restricted database access.

  • Authentication controls.

  • Backup procedures.

  • Activity monitoring.

  • Protection against unauthorized queries.

Customer data belonging to different organizations must be logically separated.

15. Multi-Tenant Security

Because Esyana operates as a SaaS multi-tenant platform, Sadeid implements controls designed to ensure customer separation.

Controls include:

  • Tenant identification.

  • Access validation.

  • Authorization checks.

  • Data filtering.

  • Permission enforcement.

Customers must not be able to access information belonging to another customer.

16. Backup Policy

Sadeid maintains backup procedures designed to protect against:

  • Hardware failures.

  • Software failures.

  • Human errors.

  • Security incidents.

Backup practices may include:

  • Automated backups.

  • Backup monitoring.

  • Secure storage.

  • Recovery testing.

17. Disaster Recovery

Sadeid maintains recovery procedures to restore service following major incidents.

Recovery objectives include:

  • Restoring application availability.

  • Recovering databases.

  • Protecting customer information.

  • Minimizing service disruption.

18. Logging and Monitoring

Sadeid may maintain logs including:

  • Login attempts.

  • User activities.

  • Administrative actions.

  • System events.

  • Security events.

  • Application errors.

Logs are used for:

  • Security monitoring.

  • Troubleshooting.

  • Incident investigation.

  • Compliance purposes.

19. Employee Security

Employees and contractors with access to systems must:

  • Follow confidentiality obligations.

  • Use approved systems.

  • Protect credentials.

  • Report security concerns.

  • Follow access policies.

Access should be removed when personnel no longer require access.

20. Third-Party Service Providers

Sadeid may use trusted providers for:

  • Cloud hosting.

  • Email delivery.

  • SMS services.

  • Payment processing.

  • Monitoring services.

  • Support tools.

Third parties should be evaluated based on:

  • Security practices.

  • Reliability.

  • Data protection capabilities.

21. Incident Response Policy

A security incident may include:

  • Unauthorized access.

  • Data exposure.

  • Malware infection.

  • Service disruption.

  • Credential compromise.

Sadeid's response process includes:

Identification

Detect and confirm the incident.

Containment

Limit damage and prevent further impact.

Investigation

Analyze:

  • Cause.

  • Scope.

  • Affected systems.

Recovery

Restore normal operations.

Review

Implement improvements to prevent recurrence.

22. Security Incident Notification

If a security incident affects Customer Data:

Sadeid will:

  • Investigate the incident.

  • Take reasonable containment measures.

  • Notify affected customers according to contractual and legal requirements.

  • Provide available information regarding the incident.

23. Physical Security

Where infrastructure providers are used, physical security is managed through those providers' facilities.

Controls may include:

  • Data center access restrictions.

  • Surveillance.

  • Environmental controls.

  • Power protection.

  • Disaster prevention systems.

24. Customer Security Recommendations

Customers should:

  • Enable MFA where available.

  • Review user permissions regularly.

  • Remove inactive users.

  • Train employees.

  • Avoid sharing accounts.

  • Use secure devices.

  • Protect exported data.

25. Security Testing

Sadeid may perform security testing including:

  • Vulnerability scanning.

  • Code security review.

  • Penetration testing.

  • Configuration assessments.

Customers must not perform security testing against Esyana without written authorization.

26. Responsible Disclosure

Sadeid encourages responsible reporting of security vulnerabilities.

Reports should include:

  • Description of the vulnerability.

  • Affected component.

  • Steps to reproduce.

  • Security impact.

Sadeid will review reports and respond appropriately.

27. Compliance

Sadeid aims to maintain security practices aligned with recognized industry standards.

Future security certifications may include:

  • ISO 27001

  • SOC 2

  • Other applicable standards

Certification does not transfer responsibility for Customer security practices.

28. Policy Updates

Sadeid may update this Information Security Policy due to:

  • Security improvements.

  • Technology changes.

  • Legal requirements.

  • Industry best practices.

The updated version will include a revised date.

29. Contact Information

Security-related questions may be directed to:

Sadeid
Registration Number: 1210822026
Hashemite Kingdom of Jordan
Website: https://esyana.com

Recommended security contact:

security@esyana.com

Appendix A – Recommended Esyana Security Roadmap

For a commercial SaaS product, Sadeid should implement the following roadmap:

Phase 1 – Basic Security

✔ HTTPS everywhere
✔ Password hashing
✔ RBAC permissions
✔ Audit logs
✔ Automated backups
✔ Firewall protection

Phase 2 – Advanced Security

✔ Multi-factor authentication
✔ Vulnerability scanning
✔ Security monitoring
✔ Automated security alerts
✔ Penetration testing
✔ Secure development reviews

Phase 3 – Enterprise Security

✔ ISO 27001 preparation
✔ SOC 2 readiness
✔ Security questionnaires for enterprise clients
✔ Dedicated security monitoring
✔ Advanced logging and SIEM integration

End of Legal Package

You now have the complete core legal package for Esyana SaaS:

  1. ✅ Terms of Service

  2. ✅ Privacy Policy

  3. ✅ Cookie Policy

  4. ✅ SaaS Subscription Agreement

  5. ✅ Service Level Agreement (SLA)

  6. ✅ Data Processing Agreement (DPA)

  7. ✅ Acceptable Use Policy

  8. ✅ Refund & Cancellation Policy

  9. ✅ Information Security Policy

For the next stage, I recommend creating operational documents for Esyana, not legal documents, such as:

  • Software Requirements Specification (SRS) for programmers

  • Database design document

  • User roles & permissions matrix

  • Work order workflow specification

  • API documentation plan

  • Security testing checklist

  • SaaS administrator manual

  • Customer onboarding manual