nawaaنواة
BUILT ON TRUST

Your people’s data
deserves care.

Implemented controls

Authenticated workspace requests are scoped to the user’s organization. Permission checks protect employee records, HR operations, workspace settings, and platform administration. The API validates inputs and records important changes in an activity log.

Web access uses an HTTP-only session cookie and an origin check for state-changing requests. API tokens expire after 12 hours. Login and registration endpoints are rate limited. Passwords are hashed.

Development release

Nawaa is currently a development implementation. It has not completed a production security audit or compliance certification. Use sample data for evaluation.

Before production

Production readiness includes MFA and SSO, account recovery and email verification, private document storage, jurisdiction-specific privacy and retention policies, infrastructure monitoring, backups and recovery testing, and an independent security review.

Payroll and payments

Country payroll rules will be confirmed separately. Subscription pricing produces estimates; payment collection, invoices, tax, and payment-provider webhooks are not yet connected.