ATHAR
Back to dashboard

Information Security Policy – ATHAR Platform

Last updated: September 19, 2026

This policy describes, in general terms, how ATHAR works to protect its users' information. Security is an ongoing practice that evolves with the system, and no system can guarantee absolute protection.

1. Access control and permissions

Access to platform data requires signing in with a valid account. Permissions are restricted by each account's role, and administrative areas are limited to authorized accounts only. A user's identity and permissions are verified before any data is shown or any action is performed.

2. User data isolation

Each user's data (their profile, achievements, narrative, and evidence) is kept tied to their own account, and one user cannot view another user's data.

3. Account and password protection

Passwords are never stored in their original form and are protected using secure hashing techniques. Controls are applied to limit unauthorized sign-in attempts, and any account can be suspended when needed. We recommend that users keep their passwords confidential and never share them.

4. Data and attachment protection

Files and attachments are stored privately and are made available only to their owner after identity verification. Controls apply to accepted file types and sizes to limit the upload of inappropriate content.

5. Audit logs

The platform keeps logs of specific sensitive operations for security and internal accountability, accessible only to authorized administrators. These logs do not include passwords.

6. Protection of credentials and secrets

Credentials and keys used to operate the platform are kept in the server environment only, and are never shown to users or sent to the browser.

7. Safe use of AI services

External AI services are used to help draft narrative text. What is sent to them is limited to the text needed for this purpose, and passwords and attached files are not sent. Drafts remain reviewable and editable by the user, who is responsible for approving the final content.

8. Backup and business continuity

The platform includes mechanisms for data backup and recovery, which continue to be developed as part of the platform’s operational readiness requirements.

9. Handling security incidents

We encourage users to report any security concern or suspicion through the in-platform "Support" page, and reports are reviewed by the responsible team.

10. Security review and updates

Security controls are reviewed and updated when needed, and this policy may change as the platform evolves. The last-updated date appears at the top of this page.