Security and Data Residency
A brokerage CRM holds identity documents, financial capacity and years of private conversation. The questions worth asking about it are specific and answerable — and most vendor security pages avoid them.
AqarQore · Updated 30 August 2026 · 7 min read
The short answer
AqarQore enforces role-based access server-side, mandatory TOTP multi-factor authentication, sub-60-second session revocation and regional data hosting options across the UAE, Qatar and Saudi Arabia. We hold no regulatory certification and do not claim one — the controls are real, the badge is not.
Access control
The meaningful question is not whether a product has permissions — everything does — but where the permission is enforced.
| Interface-level restriction | Server-enforced boundary | |
|---|---|---|
| What happens | Data is sent, then hidden in the UI | Data is never returned to that user |
| Bypassable? | Yes — developer tools, or the API directly | No |
| Typical symptom | A hidden field visible in a network response | Nothing to find |
This matters in a brokerage more than in most businesses, because agents compete with each other. A permission model that merely hides a colleague's pipeline from the interface is not a control — it is a convention.
Multi-factor authentication is mandatory rather than optional, using TOTP. Optional MFA in a business where staff turn over frequently is MFA that a meaningful share of accounts will not have.
Offboarding and session revocation
Agent turnover is high in this industry, and offboarding is where most CRM security actually fails — not through attack, but through an account nobody remembered to close.
The specific gap to ask about is active sessions. Disabling a login does not always end a session already running on someone's phone. If revocation only takes effect at the next token refresh, an ex-employee may retain access for hours after you believed you had removed it.
- Revocation should propagate in under a minute, sessions included.
- It should be one action, not a checklist across several screens.
- The event should be logged, so you can evidence when access ended.
This is also why WhatsApp conversations belong on an agency-owned number rather than a personal handset — revoking system access does nothing about a client relationship living on a phone that walks out with its owner. See WhatsApp lead qualification.
Data residency
Saudi Arabia's Personal Data Protection Law and the UAE's data protection framework both make the physical location of data a live question rather than a technicality. AqarQore offers regional hosting options for the UAE, Qatar and Saudi Arabia.
When evaluating any vendor on this, insist on a specific answer:
| Question | Unacceptable answer | Acceptable answer |
|---|---|---|
| Which country holds our data? | "The cloud" or a provider brand name | A named country and region |
| Does it leave that region? | Silence, or "for processing" | A clear statement, including backups |
| Where are backups held? | Unaddressed | Named, with the same residency guarantee |
| Who can access it internally? | "Only authorised staff" | A described process with logging |
Backups are the row most often skipped. Data resident in-region with backups replicated elsewhere is not resident in-region.
Logging and accountability
Logging is what converts a security claim into something you can evidence. Without it you cannot answer a client asking who saw their file, establish what a departing employee accessed, or determine whether an incident happened at all.
The same principle runs through commission approvals, where an immutable record of who approved what and when is the difference between a control and a status field — see commission approvals.
What we do not claim
Security pages tend to imply more than they state. Ours should be readable in the opposite direction, so here is the boundary in plain terms.
| We provide | We do not claim |
|---|---|
| Server-enforced role-based access | A regulatory certification |
| Mandatory TOTP multi-factor authentication | That we make your organisation compliant |
| Sub-60-second session revocation | Immunity from every attack class |
| Regional hosting options (UAE, Qatar, KSA) | Sovereign hosting in a formal legal sense |
| Access and activity logging | That logging substitutes for your own policies |
If a vendor tells you their product makes you compliant with the PDPL or any other framework, ask which authority issued that certification and for what scope. The regulatory picture for Saudi brokerages is covered in the compliance guide.
Vendor checklist
Ask all of these of every vendor on your shortlist, including us.
- Where is our data physically hosted, and where are the backups?
- Is access enforced server-side or in the interface?
- Is multi-factor authentication mandatory or optional?
- How fast is access revoked, and does that include active sessions?
- What is logged, and how long is it retained?
- What is the export format and deletion process if we leave?
- Do you hold any certification — and if so, from whom, for what scope?
Frequently asked questions
Where is our data hosted?+
AqarQore offers regional data hosting options for the UAE, Qatar and Saudi Arabia. Ask any vendor for a physical location rather than a cloud-provider brand name — "AWS" is not an answer to "which country".
Is AqarQore certified compliant with GCC data protection law?+
No, and we will not claim otherwise. Compliance is a property of how an organisation operates, not a badge software carries on your behalf. What we provide is server-enforced access control, mandatory multi-factor authentication, rapid session revocation and regional hosting options — the controls that make your own compliance position defensible.
What happens when an agent leaves?+
Access should be revocable in under a minute, and that must include active sessions, not just the login. An agent who is logged in on a phone at the moment you disable their account should lose access immediately, not at the next token refresh.
Can an administrator see everything?+
Role-based access boundaries are enforced server-side, so what a user cannot see is not merely hidden in the interface — it is not returned to their client at all. That distinction matters: interface-level restrictions are bypassable by anyone who opens developer tools.
Is activity logged?+
Yes. If you cannot see who accessed a client record and when, you cannot investigate anything — which means you cannot answer a client asking who saw their file, or establish what an ex-employee accessed before leaving.
What happens to our data if we leave?+
You should have a documented export format and deletion process agreed before you sign, not discovered afterwards. Ask every vendor this question, us included, and get the answer in writing.