Security is the product, not a feature
Security isn't a bolt-on feature here. Al Mahdi Fast Technologies Pvt. Ltd. operates mission-critical infrastructure for governments, intelligence agencies, and global enterprises. Here's how we protect it — and how we protect you.
24/7
Secure Operations
Daily
Encrypted Backups
40+
Nations Served
2017
Operating Since
Defense in depth, by default
Every layer of AftPak's own infrastructure is held to the same standard we build for our clients.
Access Control
Role-based access across every system, TOTP two-factor authentication for administrative and client accounts, and enforced credential rotation on first login.
Threat Monitoring
Continuous uptime and error monitoring across production infrastructure, with automated alerting the moment an anomaly is detected.
Backups & Recovery
Automated, encrypted backups of client data and files, with restore procedures verified on a recurring basis — not just written down.
Rate Limiting & Abuse Prevention
Login throttling, IP-based rate limiting, and bot-abuse defenses protect authentication and public intake channels from automated attack.
Change Control
Every code change is linted, type-checked, tested, and built in an isolated CI pipeline before it is ever considered for production.
Audit Logging
Administrative actions are recorded in an internal audit log, giving us a verifiable trail for every privileged operation.
Engineered against recognized frameworks
Formal certification, where required, is scoped and documented per engagement. Full detail lives in our Compliance & Export Control policy.
Policies you can read in full, not just summarized
Privacy Policy
How we collect, use, and protect information submitted through this site.
Terms of Service
Terms governing use of the AftPak website, intake wizard, and Client Portal.
Compliance & Export Control
Our approach to export control, sanctions compliance, and regulatory alignment.
Vulnerability Disclosure Policy
How to report a security vulnerability affecting AftPak systems or this website.
security.txt
Machine-readable security contact information, per RFC 9116.
Show your visitors we're behind you
Embed a live status badge on your own site — it always reflects our current Trust Center status.
<a href="https://aftpak.com/trust"><img src="https://aftpak.com/api/trust-badge.svg" alt="Secured by AftPak" width="220" height="48" /></a>Your data, handled deliberately
Client Portal and Admin Panel sessions rely on a single essential, functional cookie — we do not use third-party advertising or cross-site tracking cookies, and site analytics are collected using a self-hosted, cookieless platform.
For engagements involving air-gapped, on-premise, or sovereign GovCloud deployment environments, additional data residency and access controls are documented in the applicable Statement of Work.
Found a vulnerability affecting AftPak systems or this website? Report it confidentially to inquiries@aftpak.com rather than disclosing it publicly, following our Vulnerability Disclosure Policy.
Read the full policy detail
Our Privacy Policy and Compliance & Export Control pages cover the legal and regulatory specifics behind everything summarized here.