WorkMajal
Security

Security by architecture.

WorkMajal uses authenticated company membership, tenant-isolated data paths, server-authorized devices, server-side punch validation, role-based access, immutable punch records and append-only correction/audit history. Client-side code is never treated as the authority for sensitive operations.

Tenant Isolation

Company records are separated by tenant and access is checked against authenticated company claims.

Server Validation

Sensitive operations such as device authorization and punches are accepted only after backend validation.

Auditability

Original punches remain immutable while corrections create a separate history rather than rewriting source records.