Data Protection Policy
Last Updated: August 18, 2026
At Ruhanir Engine, data security is not an after-thought; it is a fundamental architectural building block. This Data Protection Policy outlines our database design, encryption protocols, backup regimes, and compliance utilities that keep your organization's sensitive files and customer databases safe.
1. PostgreSQL Database Isolation (RLS)
Ruhanir Engine utilizes a single multi-tenant database structure designed for high scale and speed. To prevent accidental data leaks or cross-tenant exposures:
- Every database table is configured with PostgreSQL Row-Level Security (RLS) policies.
- Each query issued by our API is verified against a secure `tenant_id` session context linked to the logged-in user.
- Tenants are physically isolated at the software layer, ensuring that a database query from Tenant A can never retrieve rows belonging to Tenant B.
2. Data Encryption Standards
- Data in Transit: All web traffic, API transactions, and socket connections are encrypted using TLS 1.3 (Transport Layer Security) with modern cipher suites.
- Data at Rest: Tenant databases, file uploads (prescriptions, student profiles, inventory spreadsheets), and backups are encrypted at rest using industry-standard AES-256 keys managed by Supabase infrastructure.
3. Access Control & RBAC
We implement Role-Based Access Control (RBAC) to ensure that only authorized users have access to specific data panels. Admin staff roles (e.g. support, billing, provisioning) are restricted via granular permissions. General Ruhanir Engine staff have no direct access to tenant databases or private customer files, unless explicitly requested for technical debugging.
4. Automated Backups & Restore Systems
We have established a robust business continuity plan to guard against data corruption or hardware failures:
- Daily Snapshots: Complete database backups are performed automatically every 24 hours.
- Geographical Redundancy: Backups are securely replicated across multiple geographic cloud zones.
- Console Restore Utilities: Tenant administrators have access to dashboard tools to download data snapshots or schedule point-in-time recoveries in the event of human errors.
5. System Audit Logs & Monitoring
All write operations, privilege modifications, and login attempts are logged in our immutable System Audit Trail. Tenant administrators can view their local audit trail via the `/app/audit` panel to track staff logins, settings adjustments, and record additions. Security systems block brute-force attempts and issue alerts for suspicious IP address access.
6. GDPR Compliance Tools
We provide tools for tenants to perform GDPR audits. This includes:
- Data Portability: One-click export of customer databases in CSV/JSON formats.
- Right to be Forgotten: Purging mechanisms that overwrite or delete specific customer tables on tenant command.
