Skip to main content
Trust Center

Security is the product, not a feature

Al Mahdi Fast Technologies Pvt. Ltd. operates mission-critical infrastructure for governments, intelligence agencies, and global enterprises. Here's how we protect it — and how we protect you.

24/7

Secure Operations

Daily

Encrypted Backups

40+

Nations Served

2017

Operating Since

Infrastructure Controls

Defense in depth, by default

Every layer of AftPak's own infrastructure is held to the same standard we build for our clients.

Access Control

Role-based access across every system, TOTP two-factor authentication for administrative and client accounts, and enforced credential rotation on first login.

Threat Monitoring

Continuous uptime and error monitoring across production infrastructure, with automated alerting the moment an anomaly is detected.

Backups & Recovery

Automated, encrypted backups of client data and files, with restore procedures verified on a recurring basis — not just written down.

Rate Limiting & Abuse Prevention

Login throttling, IP-based rate limiting, and bot-abuse defenses protect authentication and public intake channels from automated attack.

Change Control

Every code change is linted, type-checked, tested, and built in an isolated CI pipeline before it is ever considered for production.

Audit Logging

Administrative actions are recorded in an internal audit log, giving us a verifiable trail for every privileged operation.

Compliance Alignment

Engineered against recognized frameworks

Formal certification, where required, is scoped and documented per engagement. Full detail lives in our Compliance & Export Control policy.

ISO/IEC 27001NIST SP 800-53GDPRPCI-DSSAerospace SPARTA MatrixNASA Mission-Assurance Practices
Data Handling

Your data, handled deliberately

Client Portal and Admin Panel sessions rely on a single essential, functional cookie — we do not use third-party advertising or cross-site tracking cookies, and site analytics are collected using a self-hosted, cookieless platform.

For engagements involving air-gapped, on-premise, or sovereign GovCloud deployment environments, additional data residency and access controls are documented in the applicable Statement of Work.

Found a vulnerability affecting AftPak systems or this website? Report it confidentially to inquiries@aftpak.com rather than disclosing it publicly — we acknowledge good-faith reports in a reasonable timeframe.

Read the full policy detail

Our Privacy Policy and Compliance & Export Control pages cover the legal and regulatory specifics behind everything summarized here.