Authorization
Server-side policies and permission gates. Tenant organization scoping on business data.
Practical controls for a financial back-office. No fabricated certifications.
Server-side policies and permission gates. Tenant organization scoping on business data.
CSRF protection, secure cookies on HTTPS, login throttling, inactive-user blocking.
Reversal-based corrections, idempotent settlement keys, read-only integrity checks.
Role-gated CSV exports with spreadsheet formula-injection mitigation.
Timestamped database dumps stored outside the public document root.
HTTPS with HTTP redirect on the KHATAIQ staging host.