Security

Your data is safe with us

Security is built into every layer of Ayidhu — from the infrastructure we run on to how we handle your credentials.

99.9% Uptime SLA
🔒TLS 1.3 Encryption
🏢Data isolated per tenant
🌐Cloudflare infrastructure
🔑MFA enforced

How we protect your data

Encryption at rest and in transit

All data stored in Cloudflare D1 and R2 is encrypted at rest. All traffic is encrypted with TLS 1.3 — we enforce HTTPS everywhere with no fallback to HTTP.

Multi-tenant isolation

Every organization gets its own isolated workspace. Every database query is scoped by tenant ID — there is no shared data between organizations at any level.

Secure authentication

Authentication is powered by Clerk with JWT validation on every request. We support SSO / SAML on Enterprise plans. MFA is available for all accounts.

Role-based access control

Fine-grained RBAC lets administrators control exactly what each team member can see and do. Field-level visibility is configurable per role and included in every plan.

Audit logs

Every create, update, and delete action is logged with the user ID, timestamp, and changed values. Audit logs are available on Enterprise plans and retained for 12 months.

Automatic backups

Your data is backed up continuously via Cloudflare D1's built-in replication. Point-in-time restore is available on request for Enterprise customers within the retention window.

Infrastructure

Built on Cloudflare's global network

Ayidhu runs on Cloudflare Workers and Pages — a distributed edge network with data centers in 300+ cities worldwide. Your data is close to your team, with built-in DDoS protection and WAF filtering on every request.

  • Workers run on isolated V8 isolates — no shared process memory
  • D1 SQLite databases with automatic replication
  • R2 object storage with server-side encryption
  • All requests pass through Cloudflare WAF
  • DDoS mitigation built in at the network layer

Security checklist

  • HTTPS enforced on all endpoints
  • JWT signed and verified on every API request
  • Tenant ID scoped on every database query
  • Input validation and SQL injection prevention
  • Rate limiting on authentication endpoints
  • Secrets stored in Cloudflare Secrets (never in code)
  • Dependency updates reviewed weekly
  • Incident response plan documented

Responsible disclosure

Found a security vulnerability? We take all reports seriously. Please email us at [email protected] with a description of the issue, reproduction steps, and potential impact.

We aim to acknowledge all reports within 24 hours and resolve confirmed vulnerabilities within 14 days. We do not pursue legal action against good-faith security researchers.

Questions about security?

Our team is happy to answer any security or compliance questions before you sign up.