INFORMATION SECURITY POLICY
Esyana Field Maintenance Management Platform
Document Version: 1.0
Effective Date: 26 July 2026
Last Updated: 26 July 2026
INFORMATION SECURITY POLICY
This Information Security Policy ("Policy") defines the security principles, controls, responsibilities, and procedures used by Sadeid to protect information processed through the Esyana Field Maintenance Management Platform ("Esyana", "Platform", "Service").
Sadeid is registered in the Hashemite Kingdom of Jordan under Registration Number 1210822026.
This Policy applies to:
Esyana software systems
Cloud infrastructure
Databases
Applications
APIs
Customer data
Internal systems
Employees
Contractors
Service providers
1. Purpose
The purpose of this Policy is to establish a framework to:
Protect confidentiality of customer information.
Maintain integrity of business data.
Ensure availability of the Esyana platform.
Prevent unauthorized access.
Reduce cybersecurity risks.
Establish security responsibilities.
Support compliance with applicable laws and contractual obligations.
2. Security Principles
Sadeid follows these core security principles:
Confidentiality
Information is accessible only to authorized users.
Integrity
Information must remain accurate and protected against unauthorized modification.
Availability
The Platform should remain accessible and operational for customers.
Least Privilege
Users and employees receive only the access required to perform their responsibilities.
Defense in Depth
Multiple layers of security controls are used to reduce risk.
3. Scope of Protected Information
Information protected under this Policy includes:
Customer Data
Client information
Asset records
Device information
Work orders
Maintenance history
Reports
Photos
Documents
Invoices
Inventory information
Warranty information
Personal Information
User names
Email addresses
Phone numbers
Employee information
Technician information
Login information
Company Information
Source code
Technical documentation
Infrastructure details
Business information
Internal procedures
4. Information Security Responsibilities
Sadeid Responsibilities
Sadeid is responsible for:
Maintaining security controls.
Protecting customer data.
Monitoring infrastructure.
Managing vulnerabilities.
Responding to security incidents.
Training authorized personnel.
Improving security practices.
Customer Responsibilities
Customers are responsible for:
Protecting account credentials.
Managing user permissions.
Training their employees.
Reviewing access rights.
Protecting their own devices.
Reporting suspected security issues.
5. Access Control Policy
Sadeid implements access control measures designed to prevent unauthorized access.
Controls include:
Unique user accounts.
Role-Based Access Control (RBAC).
Permission management.
Administrative access restrictions.
User activity logging.
Account deactivation procedures.
6. Role-Based Access Control
Esyana uses permission-based access management.
Customers can configure access according to roles such as:
Super Administrator
Company Administrator
Service Manager
Maintenance Supervisor
Technician
Warehouse Manager
Accountant
Client Portal User
Read-Only User
Each role should have only the permissions necessary for its function.
7. Authentication Security
Sadeid implements authentication controls including:
Secure password storage.
Password complexity requirements.
Session management.
Login monitoring.
Account lockout mechanisms where appropriate.
Recommended additional controls:
Multi-factor authentication (MFA).
Single Sign-On (SSO) for enterprise customers.
8. Password Policy
Users should:
Use strong passwords.
Avoid password reuse.
Keep passwords confidential.
Change passwords when compromise is suspected.
Passwords must never be:
Stored in plain text.
Shared between users.
Sent through unsecured communication channels.
9. Data Encryption
Sadeid uses encryption technologies designed to protect information.
Data in Transit
Communication between users and Esyana systems should be protected using secure protocols such as:
HTTPS
TLS encryption
Data at Rest
Where applicable, stored information should be protected using encryption mechanisms provided by the infrastructure environment.
Examples:
Databases
Backups
Storage systems
10. Application Security
Sadeid follows secure software development practices.
Security practices include:
Secure coding standards.
Code reviews.
Dependency monitoring.
Input validation.
Authentication checks.
Authorization checks.
Error handling.
Security testing before major releases.
11. Secure Development Lifecycle (SSDLC)
Software development activities should include:
Planning
Identify security requirements.
Assess risks.
Development
Follow secure coding practices.
Avoid insecure libraries.
Review sensitive functionality.
Testing
Testing may include:
Functional testing.
Security testing.
Vulnerability scanning.
Penetration testing.
Deployment
Secure configuration.
Controlled releases.
Monitoring after deployment.
12. Vulnerability Management
Sadeid maintains procedures to identify and address security weaknesses.
Activities may include:
Security updates.
Dependency monitoring.
Vulnerability assessments.
Infrastructure reviews.
Security testing.
Critical vulnerabilities should receive priority remediation.
13. Network Security
Security controls may include:
Firewalls.
Network segmentation.
Access restrictions.
Secure communication protocols.
Monitoring systems.
Administrative access to production systems should be restricted to authorized personnel.
14. Database Security
Database security controls include:
Restricted database access.
Authentication controls.
Backup procedures.
Activity monitoring.
Protection against unauthorized queries.
Customer data belonging to different organizations must be logically separated.
15. Multi-Tenant Security
Because Esyana operates as a SaaS multi-tenant platform, Sadeid implements controls designed to ensure customer separation.
Controls include:
Tenant identification.
Access validation.
Authorization checks.
Data filtering.
Permission enforcement.
Customers must not be able to access information belonging to another customer.
16. Backup Policy
Sadeid maintains backup procedures designed to protect against:
Hardware failures.
Software failures.
Human errors.
Security incidents.
Backup practices may include:
Automated backups.
Backup monitoring.
Secure storage.
Recovery testing.
17. Disaster Recovery
Sadeid maintains recovery procedures to restore service following major incidents.
Recovery objectives include:
Restoring application availability.
Recovering databases.
Protecting customer information.
Minimizing service disruption.
18. Logging and Monitoring
Sadeid may maintain logs including:
Login attempts.
User activities.
Administrative actions.
System events.
Security events.
Application errors.
Logs are used for:
Security monitoring.
Troubleshooting.
Incident investigation.
Compliance purposes.
19. Employee Security
Employees and contractors with access to systems must:
Follow confidentiality obligations.
Use approved systems.
Protect credentials.
Report security concerns.
Follow access policies.
Access should be removed when personnel no longer require access.
20. Third-Party Service Providers
Sadeid may use trusted providers for:
Cloud hosting.
Email delivery.
SMS services.
Payment processing.
Monitoring services.
Support tools.
Third parties should be evaluated based on:
Security practices.
Reliability.
Data protection capabilities.
21. Incident Response Policy
A security incident may include:
Unauthorized access.
Data exposure.
Malware infection.
Service disruption.
Credential compromise.
Sadeid's response process includes:
Identification
Detect and confirm the incident.
Containment
Limit damage and prevent further impact.
Investigation
Analyze:
Cause.
Scope.
Affected systems.
Recovery
Restore normal operations.
Review
Implement improvements to prevent recurrence.
22. Security Incident Notification
If a security incident affects Customer Data:
Sadeid will:
Investigate the incident.
Take reasonable containment measures.
Notify affected customers according to contractual and legal requirements.
Provide available information regarding the incident.
23. Physical Security
Where infrastructure providers are used, physical security is managed through those providers' facilities.
Controls may include:
Data center access restrictions.
Surveillance.
Environmental controls.
Power protection.
Disaster prevention systems.
24. Customer Security Recommendations
Customers should:
Enable MFA where available.
Review user permissions regularly.
Remove inactive users.
Train employees.
Avoid sharing accounts.
Use secure devices.
Protect exported data.
25. Security Testing
Sadeid may perform security testing including:
Vulnerability scanning.
Code security review.
Penetration testing.
Configuration assessments.
Customers must not perform security testing against Esyana without written authorization.
26. Responsible Disclosure
Sadeid encourages responsible reporting of security vulnerabilities.
Reports should include:
Description of the vulnerability.
Affected component.
Steps to reproduce.
Security impact.
Sadeid will review reports and respond appropriately.
27. Compliance
Sadeid aims to maintain security practices aligned with recognized industry standards.
Future security certifications may include:
ISO 27001
SOC 2
Other applicable standards
Certification does not transfer responsibility for Customer security practices.
28. Policy Updates
Sadeid may update this Information Security Policy due to:
Security improvements.
Technology changes.
Legal requirements.
Industry best practices.
The updated version will include a revised date.
29. Contact Information
Security-related questions may be directed to:
Sadeid
Registration Number: 1210822026
Hashemite Kingdom of Jordan
Website: https://esyana.com
Recommended security contact:
Appendix A – Recommended Esyana Security Roadmap
For a commercial SaaS product, Sadeid should implement the following roadmap:
Phase 1 – Basic Security
✔ HTTPS everywhere
✔ Password hashing
✔ RBAC permissions
✔ Audit logs
✔ Automated backups
✔ Firewall protection
Phase 2 – Advanced Security
✔ Multi-factor authentication
✔ Vulnerability scanning
✔ Security monitoring
✔ Automated security alerts
✔ Penetration testing
✔ Secure development reviews
Phase 3 – Enterprise Security
✔ ISO 27001 preparation
✔ SOC 2 readiness
✔ Security questionnaires for enterprise clients
✔ Dedicated security monitoring
✔ Advanced logging and SIEM integration
End of Legal Package
You now have the complete core legal package for Esyana SaaS:
✅ Terms of Service
✅ Privacy Policy
✅ Cookie Policy
✅ SaaS Subscription Agreement
✅ Service Level Agreement (SLA)
✅ Data Processing Agreement (DPA)
✅ Acceptable Use Policy
✅ Refund & Cancellation Policy
✅ Information Security Policy
For the next stage, I recommend creating operational documents for Esyana, not legal documents, such as:
Software Requirements Specification (SRS) for programmers
Database design document
User roles & permissions matrix
Work order workflow specification
API documentation plan
Security testing checklist
SaaS administrator manual
Customer onboarding manual