01Operator and contact details
Manara One operates this website through two entities: [UAE ENTITY LEGAL NAME], licensed in the Emirate of Sharjah under licence number [LICENCE NO.], with its address at [SHARJAH ADDRESS]; and [US ENTITY LEGAL NAME], established in [US STATE], with its address at [US ADDRESS]. The relevant entity is identified in a customer’s signed agreement. Website legal correspondence may be sent to legal@manaraone.com; privacy and Data Protection Officer enquiries to privacy@manaraone.com; security reports to security@manaraone.com; and accessibility feedback to accessibility@manaraone.com. Please identify the relevant service and request without including unnecessary personal or confidential information.
02Shared responsibility and security scope
Security is a shared responsibility between Manara One, service providers and customers. Manara One maintains the controls within its service scope; customers manage authorised users, configuration, devices and lawful use. The signed agreement defines the deployment, responsibilities and any service commitments. This page describes controls and disclosure expectations, not a certification or guarantee against every threat. No independent certification claim is made. Administrators should assess their environment, configure available protections and review risks when integrating new services. Public website interactions and customer ERP processing are distinct; sensitive customer records should never be submitted to the public Solution advisor or an ordinary website enquiry.
03Permissions, isolation and least privilege
Role, field and company permissions determine authorised access in Manara One. Access should follow least privilege and be reviewed when responsibilities change or users leave. Tenant isolation includes row-level security for Manara Hub data in Supabase EU. Customers must keep company assignments and permissions accurate and avoid shared credentials. Manara AI tools are read only under the user’s own permissions and do not elevate access. These protections depend on correct configuration and authorised integration use. Do not attempt to circumvent a denied operation through another account or endpoint. Report unexpected access privately and stop testing before another party’s information is exposed.
04Encryption, secrets and operational records
Data is protected in transit using TLS, with encryption at rest and controlled access in the hosting environment. Integration secrets are kept in a vault rather than exposed in ordinary ERP records or browser code. Access to credentials must be limited to authorised operational needs and reviewed as part of service administration. Audit trails and append-only operating records support investigation and accountability; they are not a substitute for reviewing access. Customers should protect their own endpoints, networks and exported records, and must not disclose credentials in support messages. Provider processing terms and transfer safeguards are described in the Data Protection Statement.
05Signed devices and camera boundaries
Device endpoints use HMAC signatures and a replay window to validate messages and limit replayed requests. Customers and integrators must safeguard signing secrets and preserve the required message validation. Camera access uses signed links valid for five minutes through the media gateway. No video is stored in the ERP and no face recognition is provided. Camera events are append-only. Do not forward a signed link to an unauthorised person or treat its short validity as permission to disclose media. Biometric templates are never collected or stored. Phone tracking and high risk device processing require the customer’s applicable DPIA and lawful operational controls.
06AI controls and incident coordination
Customer Manara AI pseudonymises personal data before it reaches the model provider, applies the user’s permissions and maintains append-only call logs. A recorded DPA and approved DPIA are required before use is enabled. Budget hard stops and a kill switch support operational control. Customers remain responsible for reviewing output and ensuring authorised processing. Security incidents are assessed for containment, impact and evidence preservation, with the relevant customer informed under the agreement. Where a personal data breach requires notification, we coordinate responsibilities under applicable law, including notification to the UAE Data Office and affected individuals where required. No universal notification deadline is asserted.
07Responsible disclosure and safe harbour
Send vulnerability reports privately to security@manaraone.com. Include the affected URL or feature, reproduction steps and a minimal demonstration that does not expose personal data. Our acknowledgement target is five business days; this is not a remediation deadline. For good faith research that follows these conditions, we will not initiate legal action solely for the authorised research and will treat it as permitted under this policy. This safe harbour cannot bind third parties or override law. Stop when unexpected data becomes visible, avoid copying it, and tell us promptly. Obtain written permission before any test outside ordinary, non-disruptive public interaction.
08Research limits and coordinated communication
Do not test in ways that harm data or availability, use malware, social engineering or credential attacks, access another tenant, persist in a system or extract records. Do not test third party providers without their permission. Share only the minimum evidence needed and do not publish sensitive exploit details while coordination is ongoing. We may request clarification or an agreed validation step through the private reporting channel. Researchers should preserve confidentiality and delete inadvertently received data as instructed where lawful. Customers should report suspected incidents immediately through security@manaraone.com. These expectations protect affected people and do not promise a reward, certification or immunity from unrelated unlawful conduct.