Security Measures
SalamaShop protects buyers, sellers, and operators with layered encryption, access control, monitoring, and auditability.
End-to-End Encryption
TLS protects data in transit; sensitive documents and tokens are encrypted before storage.
- HTTPS/TLS for portal, API, and webhook traffic
- Encrypted document access tokens for KYC and dispute evidence
- Hashed API bearer tokens and OTP verification codes
Multi-Factor Authentication
Staff and privileged roles must complete a second factor before portal or API access.
- Email OTP challenge for mandatory staff roles
- Configurable challenge TTL and role policy
- API endpoints for 2FA verify, enable, and disable
KYC Verification
Seller identity verification with tiered badges and compliance review workflows.
- Bronze, Silver, and Gold seller verification tiers
- Document upload with private storage
- Compliance review queue with audit logging
AML Monitoring
Transaction monitoring flags unusual amounts, velocity, and high-risk counterparties.
- Automated screening on deposits and releases
- Configurable amount and velocity thresholds
- AML alert queue for compliance review
Fraud Detection
Seller risk scoring using account age, verification, disputes, and transaction patterns.
- Rule-based risk scores and factor breakdown
- Triggered on orders, disputes, and registration
- Admin risk seller dashboard with recalculation
Audit Logs
Immutable-style activity records for authentication, escrow, KYC, and admin actions.
- Actor, action, subject, metadata, and IP capture
- Portal audit trail and workflow activity logs
- Webhook and notification history
Data Encryption at Rest
Application-level encryption for credentials, documents, and backup archives.
- Bcrypt password hashing
- Laravel encryption for sensitive file access tokens
- Optional encrypted database backups
Secure Backups
Scheduled database exports stored with retention and optional encryption.
- Artisan backup command with retention policy
- Encrypted archive option using application key
- Daily scheduled backup job
Role-Based Access Control
Spatie permission matrix separating managers, system admins, and operational roles.
- Granular manage-* permissions
- Role hierarchy guards for account administration
- Portal navigation and controller authorization
API Security
Token authentication, rate limiting, security headers, and webhook signature verification.
- Bearer token auth with expiry and role scoping
- Per-route rate limits for auth, OTP, and uploads
- HMAC webhook signatures and CSP security headers