Enterprise-grade safeguards

Security Measures

SalamaShop protects buyers, sellers, and operators with layered encryption, access control, monitoring, and auditability.

Active

End-to-End Encryption

TLS protects data in transit; sensitive documents and tokens are encrypted before storage.

  • HTTPS/TLS for portal, API, and webhook traffic
  • Encrypted document access tokens for KYC and dispute evidence
  • Hashed API bearer tokens and OTP verification codes
Active

Multi-Factor Authentication

Staff and privileged roles must complete a second factor before portal or API access.

  • Email OTP challenge for mandatory staff roles
  • Configurable challenge TTL and role policy
  • API endpoints for 2FA verify, enable, and disable
Active

KYC Verification

Seller identity verification with tiered badges and compliance review workflows.

  • Bronze, Silver, and Gold seller verification tiers
  • Document upload with private storage
  • Compliance review queue with audit logging
Active

AML Monitoring

Transaction monitoring flags unusual amounts, velocity, and high-risk counterparties.

  • Automated screening on deposits and releases
  • Configurable amount and velocity thresholds
  • AML alert queue for compliance review
Active

Fraud Detection

Seller risk scoring using account age, verification, disputes, and transaction patterns.

  • Rule-based risk scores and factor breakdown
  • Triggered on orders, disputes, and registration
  • Admin risk seller dashboard with recalculation
Active

Audit Logs

Immutable-style activity records for authentication, escrow, KYC, and admin actions.

  • Actor, action, subject, metadata, and IP capture
  • Portal audit trail and workflow activity logs
  • Webhook and notification history
Partial

Data Encryption at Rest

Application-level encryption for credentials, documents, and backup archives.

  • Bcrypt password hashing
  • Laravel encryption for sensitive file access tokens
  • Optional encrypted database backups
Partial

Secure Backups

Scheduled database exports stored with retention and optional encryption.

  • Artisan backup command with retention policy
  • Encrypted archive option using application key
  • Daily scheduled backup job
Active

Role-Based Access Control

Spatie permission matrix separating managers, system admins, and operational roles.

  • Granular manage-* permissions
  • Role hierarchy guards for account administration
  • Portal navigation and controller authorization
Partial

API Security

Token authentication, rate limiting, security headers, and webhook signature verification.

  • Bearer token auth with expiry and role scoping
  • Per-route rate limits for auth, OTP, and uploads
  • HMAC webhook signatures and CSP security headers