Trust & Security

Security & Compliance Overview

A plain, accurate account of how Morocco Business Gateway protects your data and runs the platform. Last updated: 21 September 2026.

1. Data in transit and at rest

  • All traffic is served over HTTPS/TLS; HTTP requests are upgraded automatically (HSTS enforced).
  • Direct messages between members are encrypted at rest (AES-256-GCM) before they are stored — not just protected by access control.
  • KYC/verification documents and every other uploaded file are stored behind access-controlled, time-limited signed URLs. A document that access control withholds is never served — there is no URL to leak.

2. Access control

  • Every API route requires authentication by default; a route is public only when explicitly marked so, not the other way around.
  • Admin actions are scoped by role and by a separate per-permission grant, not a single blanket "admin" flag.
  • Sensitive admin actions require a freshly re-authenticated session, so a stale session token cannot be replayed to perform them.
  • Rate limiting is enforced platform-wide, with stricter limits on authentication endpoints specifically (login, registration, password reset).

3. Application security

  • Security headers (including a Content-Security-Policy) are enforced in production via Helmet.
  • Cross-origin requests are restricted to our own frontend origin — the API does not accept requests from arbitrary origins.
  • Uploaded files are validated by more than their claimed type: size limits, an allowlist of MIME types, and a check of the file's actual byte signature (not just its extension or declared content type) before it is accepted.
  • No secret or credential is committed to source control; production configuration is validated at startup and the application refuses to start if a required secret is missing or a production-unsafe setting (e.g. a test payment mode) is left enabled.

4. Payments

Card payments are processed by DashyPay, a licensed Moroccan payment provider. Cardholder data is entered on DashyPay's own hosted payment page and never reaches our servers. Payment confirmations arrive by webhook, which we verify with an HMAC signature check before acting on it, and every webhook is processed exactly once even if DashyPay retries delivery. A payment can only be marked as settled by that verified webhook — no administrator can mark a payment or a commission as paid by hand.

5. Verification — what "verified" means today

Every company, partner, expert, and service provider on the platform must upload a required set of identity/registration documents (e.g. Registre de Commerce, ICE certificate, national ID of the legal representative) before being marked Verified. Each document is reviewed individually by our team before an account is approved.

Disclosed limitation: today, verification is a manual document review — we do not yet perform an automated real-time check against Morocco's national business registry (OMPIC). This is a deliberate, near-term roadmap item, not an oversight. A "Verified" badge means our team reviewed the submitted documents, not that a government registry was queried live.

6. Sub-processors

The following third parties process data on our behalf, each for a narrow, specific purpose:

  • Cloudflare — bot/abuse protection (Turnstile) and file storage (R2).
  • Resend — transactional email delivery.
  • DashyPay — card payment processing.
  • Our infrastructure host — operates the servers the platform runs on.

We never sell member data, and we never share it with a third party outside this list except at your direction (e.g. the counterpart you choose to connect with).

7. Data retention & deletion

Data is retained for the duration of your relationship with the platform, then for the period required by our legal and accounting obligations, after which it is deleted or anonymized. See our Privacy Policy for the full detail required under Moroccan law 09-08.

8. Operational reliability

The platform runs a dedicated health-check that continuously verifies both the database and the background job queue are reachable, and every request is tagged with a correlation id that ties a user-facing error back to the exact request that caused it — which is what our team uses to investigate an issue you report. We are actively investing in broader, always-on production monitoring as the platform scales; if you need specifics on our current incident-response process for your security review, contact us directly (below) and we will walk you through it.

9. Legal entity

Morocco Business Gateway is operated by MT Performance, RC 528651, ICE 002993731000042, based in Casablanca, Maroc.

10. Questions, or need a signed DPA?

Read our Data Processing Agreement for the contractual terms governing how we handle data on your behalf. For anything not covered here — a security questionnaire, a penetration-test summary request, or a specific compliance question — write to contact@moroccobusinessgateway.com.