Security
Security is scoped, not guessed. Security expectations, hosting choices, access controls, backups, documentation, and handover requirements are scoped according to the engagement and operating model.
Practical security practices
- Least-privilege access where possible.
- Multi-factor authentication recommended for client accounts and shared systems.
- Separate admin access where available.
- Password manager recommended for shared credentials.
- Access review during handover.
- Avoiding unnecessary credential sharing.
- Documentation for agreed systems.
- Backup and export planning where scoped.
- Role-based access where scoped.
- Audit logs where scoped.
- Clear handover responsibilities.
- Third-party infrastructure choices depend on selected provider and client requirements.
What Baraka Hall controls
- Site and system structure
- Access planning
- Documentation
- Workflow logic
- Handover process
- Admin operating layer
- Security-conscious implementation choices
What depends on the engagement
- Hosting provider
- Client subscriptions
- Third-party apps
- Payment providers
- AI providers
- Email providers
- Data retention rules
- Support level
- Backup requirements
- Access ownership
- Code ownership and licence model
Provider assurance
Baraka Hall may build with reputable infrastructure, hosting, email, payment, automation, AI, analytics, and operational providers where appropriate. Selected providers may offer security controls, certification programmes, data protection agreements, regional hosting, encrypted storage, role-based access, monitoring, or security scanning.
Provider certifications apply to the relevant provider and covered services. They support the delivery environment but do not automatically make Baraka Hall or a client system independently certified. Where formal compliance evidence, audit support, security documentation, or certification-readiness work is needed, this is scoped separately.
Certification and compliance requests
Some clients need formal security, compliance, procurement, or due-diligence documentation. Baraka Hall can support these conversations by identifying relevant providers, access models, data flows, documentation requirements, and security responsibilities. Formal certifications, audits, penetration tests, legal reviews, or compliance sign-offs are scoped separately unless expressly included in the engagement.
Security without theatre
Baraka Hall does not rely on vague security theatre. The right approach depends on what is being built, who operates it, what data it handles, what third-party services are used, and what the client needs after handover. Larger or more sensitive engagements can include additional contractual security terms.
Reporting a security concern
If you believe you have found a security issue relating to Baraka Hall, write to hello@barakahall.com with a description and any evidence. Please do not test issues in ways that could affect other users.
Related pages
Baraka Hall is operated by Baraka Valley Holdings Ltd. Contact: hello@barakahall.com.