Security principles
TasheelExpress uses layered controls designed around the practical risks of language-service work: confidential documents, identity information, commercial records, account access and project communications. Public security information describes the control model without exposing internal secrets or configuration.
HTTPS and transport protection
The public website is served over HTTPS so traffic between supported browsers and the site is encrypted in transit. Secure cookies and browser security headers are used in production where applicable to reduce common web risks.
File intake and validation
Uploaded files are checked against allowed extensions, MIME or signature expectations, configured size limits and integrity controls before being associated with a request. Randomized server-side filenames help reduce predictable-path exposure, and project uploads are kept outside the public web directory where configured.
Malware protection
The hosting environment performs real-time malware protection on files uploaded through the web layer. TasheelExpress does not publish scanner commands or internal security paths. Malware analysis complements, rather than replaces, application-level file validation and safe handling.
Authentication and access control
Authenticated areas use session controls and role-based authorization. Access to project or administrative functions is limited according to role and operational need. Security-sensitive actions can require additional validation such as anti-CSRF controls, form tokens or account verification.
Application and API protection
Public forms use input validation, request-size limits, rate controls and origin checks. Public API responses are intentionally limited so they do not expose database URLs, SMTP configuration, environment variables, filesystem paths, credentials or other internal details.
Logging and operational monitoring
Security and operational events can be logged to support troubleshooting, abuse detection and incident review. Logs are treated as operational records and access is restricted. We avoid placing secrets or full sensitive documents in application logs.
Backups and resilience
Backups, database protection and recovery procedures are part of the hosting and application operating model. The exact recovery design can depend on deployment environment and project requirements; public pages do not claim certifications, recovery objectives or uptime figures that have not been independently verified.
Incident handling
When a suspected security incident affects project data or account access, the priority is containment, preservation of relevant evidence, assessment of affected systems, restoration of safe operation and notification where required by applicable law or contract.
Client responsibilities
Clients should use strong account credentials, avoid sharing login details, send only necessary information, keep their own originals, and alert us promptly if they suspect unauthorized account or project access. Highly sensitive projects should be identified before upload so additional handling requirements can be agreed.
Responsible disclosure
If you believe you have found a security issue affecting TasheelExpress, use the contact page and provide enough technical detail for investigation without accessing, altering or retaining data that does not belong to you. Do not include exploit payloads in public forms unless requested through a secure support channel.
