Security and data protection

Protect pilgrim data without slowing down your team

A practical overview of the controls built into Ziyara, what your agency controls, and the documents available for your compliance review.

Security controls built into Ziyara

Sensitive-field encryption

Sensitive identity fields, including passport numbers, are encrypted at rest with AES-256.

Encrypted connections

Traffic between your browser, mobile app and Ziyara is protected in transit with TLS.

Agency data isolation

Each agency operates in its own tenant workspace so its records are separated from other agencies.

Roles and audit history

Team permissions limit access, while Professional workspaces can review staff activity in audit logs.

Backups

Operational data is backed up regularly to support recovery from an infrastructure or application incident.

EU-based hosting

The production infrastructure and primary data storage are hosted in the European Union.

What Ziyara provides

  • Technical safeguards for the platform and its infrastructure.
  • Tools for access control, data export and account management.
  • Privacy, GDPR, DPA and sub-processor documentation for review.

What your agency controls

  • Which staff members receive accounts and permissions.
  • Which pilgrim data you collect and the lawful basis for collecting it.
  • Password hygiene, device security and timely removal of former staff.

Review the details before you register

These documents explain how data is handled, the contractual roles and the providers involved in delivering the service.

See the controls in a real workspace

Start a free trial and test roles, records and exports with your own internal process.

Start 30-day free trial