Skip to main content

    Security

    Last updated: 9/26/2026

    Our Commitment to Security

    At Sidra Innovation for IT LLC (SidraTech), security is fundamental to everything we do. As a Microsoft Solutions Partner handling enterprise data and critical business systems, we understand the importance of maintaining the highest security standards. We are committed to protecting your data, ensuring system integrity, and maintaining your trust through comprehensive security practices.

    Data Protection and Encryption

    Encryption in Transit

    All data transmitted between your browser and our servers is encrypted using industry-standard TLS/SSL protocols. This ensures that your information cannot be intercepted or read by unauthorized parties during transmission.

    Encryption at Rest

    Sensitive data stored in our databases is encrypted using AES-256 encryption or equivalent standards. We implement encryption for customer data, credentials, and any personally identifiable information.

    Data Minimization

    We collect and retain only the data necessary for providing our services. We regularly review and purge unnecessary data to minimize security exposure.

    Infrastructure Security

    Microsoft Azure Platform

    Our infrastructure is hosted on Microsoft Azure, which maintains industry-leading security certifications including ISO 27001, SOC 2, and compliance with GDPR and other international standards. Azure provides enterprise-grade physical and network security, DDoS protection, and redundancy.

    Network Security

    We implement multiple layers of network security including firewalls, intrusion detection and prevention systems (IDS/IPS), and network segmentation to isolate sensitive systems and data.

    Access Controls

    All systems implement role-based access control (RBAC) with the principle of least privilege. Access to production systems and customer data is restricted to authorized personnel only and is regularly audited.

    Monitoring and Logging

    We maintain comprehensive logging of system activities, security events, and access patterns. Logs are securely stored and regularly reviewed to detect and respond to potential security incidents.

    Application Security

    Secure Development Practices

    Our development team follows secure coding practices and OWASP guidelines. We conduct code reviews, use static analysis tools, and implement security testing throughout the development lifecycle.

    Input Validation and Sanitization

    All user inputs are validated and sanitized to prevent injection attacks, including SQL injection, cross-site scripting (XSS), and other common vulnerabilities.

    Authentication and Authorization

    We implement multi-factor authentication (MFA) for administrative access and sensitive operations. Session management follows industry best practices with secure token handling and automatic timeout.

    Dependency Management

    We regularly update and patch all software dependencies, libraries, and frameworks to address known vulnerabilities. Automated tools scan for security vulnerabilities in dependencies.

    Compliance and Certifications

    Microsoft Solutions Partner: We maintain Microsoft partner certifications and adhere to Microsoft's security and privacy requirements.

    Data Privacy: We comply with GDPR and other applicable data protection regulations.

    Industry Standards: Our security practices align with ISO 27001, SOC 2, and NIST cybersecurity frameworks.

    Regular Assessments: We conduct regular security assessments, vulnerability scans, and penetration testing to identify and address potential weaknesses.

    Employee Security

    Background Checks

    All employees with access to customer data or sensitive systems undergo background checks as permitted by local laws.

    Security Training

    Our team receives regular security awareness training covering phishing prevention, data handling, incident response, and security best practices.

    Confidentiality Agreements

    All employees sign confidentiality and data protection agreements as part of their employment.

    Incident Response

    Incident Response Plan

    We maintain a comprehensive incident response plan that defines procedures for identifying, containing, investigating, and resolving security incidents. Our team is trained to respond quickly and effectively to potential threats.

    24/7 Monitoring

    Critical systems are monitored around the clock for suspicious activity, performance issues, and potential security events. Automated alerts notify our security team of potential incidents.

    Breach Notification

    In the unlikely event of a data breach affecting your information, we will notify affected parties in accordance with applicable legal requirements and work to minimize impact.

    Business Continuity

    Backup and Recovery

    We maintain regular automated backups of all critical data with secure off-site storage. Our disaster recovery plans ensure business continuity and data availability.

    Redundancy

    Critical systems are deployed with redundancy and failover capabilities to ensure high availability and minimize downtime.

    Third-Party Security

    We carefully evaluate the security practices of third-party vendors and service providers. All vendors with access to customer data must meet our security requirements and are bound by appropriate agreements.

    Reporting Security Issues

    If you discover a security vulnerability or have concerns about our security practices, please report them immediately:

    Security Email: security@sidra-tech.com

    General Email: info@sidra-tech.com

    Phone: +962 79 518 6806

    We take all security reports seriously and will investigate and respond promptly. We appreciate responsible disclosure and work with the security community to protect our customers.

    Your Role in Security

    Security is a shared responsibility. We recommend that you:

    • Use strong, unique passwords for your accounts
    • Enable multi-factor authentication when available
    • Keep your devices and software up to date
    • Be cautious of phishing attempts and suspicious emails
    • Report any suspicious activity to us immediately
    • Protect your login credentials and do not share them

    Contact Us

    For questions about our security practices or this security page, please contact us:

    Company: Sidra Innovation for IT LLC (SidraTech)

    Email: info@sidra-tech.com

    Phone: +962 79 518 6806

    Address: Amman, Jordan