Skip to Content
GuidesSecurity

Security

Every staff account is one person: an email, a password and, once set up, an authenticator app. The same account opens the back office at <company>.cloud.majali.app and, when the person’s roles allow it, the operations app at <company>.operations.majali.app. This page explains the rules that protect that account and your company’s data.

Signing in

Sign in at your company’s own address, or at cloud.majali.app, where one form serves every company: enter your email and password once and you continue on your company’s address. A link you followed before signing in is honoured afterwards.

  • A password has at least 12 characters. Change it from Change password in the account menu.
  • Forgot your password? emails a link that works once and expires after one hour. The page never says whether an address has an account.
  • Five failed attempts for one account, or from one network address, lock sign-in for 15 minutes. The lockout is recorded in the audit log.
  • Once signed in you land in the app your roles open, or choose between the back office and the operations app when you open both.

The authenticator app

The second step of sign-in is a six-digit code from an authenticator app on your phone, such as Google Authenticator or any app that supports time-based codes.

  • Until you set one up, your password alone signs you in, and every page of the back office warns you with a link to the setup page. The setup page shows a QR code to scan with the app, then asks for the first code; you can choose Later and come back.
  • Once set up, every sign-in asks for the code, whatever your role. The code depends on your phone’s clock: if a code is refused, check the clock and try the newest code.
  • Sensitive changes need an authenticator (see below). Without one, their buttons are disabled and the way to set one up shows instead.
  • Setting up or resetting the second step is recorded in the audit log, and a reset ends your other sessions.

Recovery codes

When you set up the authenticator, the page shows ten recovery codes, each usable once. Keep them somewhere safe: one of them signs you in when your phone is not at hand. You find them again under Recovery codes in the account menu.

If you lose both the phone and the codes, your Administrator contacts Majali support, who reset your second step after checking the request. The reset is recorded in your company’s audit log.

A fresh code for sensitive changes

Some actions ask for a code from your authenticator app at the moment you send them, even though you are signed in. A code entered in the last five minutes counts. The form asks in a dialog; the change is refused without it.

AreaActions that ask for a fresh code
People and rolesSaving a role, changing someone’s roles or sign-in, inviting someone with roles.
Personal dataSeeing the full contacts of leads you do not hold, exporting a lead CSV carrying them, exporting or erasing one person’s data, the full export.
Company setupAdding, promoting or removing a domain, connecting or disconnecting storage, saving a payment connector, saving an embedding, giving a guest access to a booking.
DevelopersAPI keys and webhooks.
Network accessEvery change to the network access list and its switch.
ClosingConfirming the closure of the account.

Network access

Some companies want their back office reachable only from their own offices. Open Settings > Security > Network access to list the addresses allowed, and Settings > Security > Network access policy to switch the restriction on. Both need a role that includes managing network access (Administrators by default). The list is off until you switch it on; until then the back office is reachable from anywhere, behind sign-in and the second step as always. The list adds to those; it never replaces them.

The list

Each entry is one IPv4 or IPv6 address or a range, with a label, who created it and when, and an optional expiry: keep it for 6 hours, 1 day, 1 week or until a chosen day. A range broader than /16 (IPv4) or /48 (IPv6) lets many networks in, so saving one asks you to confirm. A company can hold up to 200 entries. Expired entries are removed automatically, each removal recorded.

Add my current address adds the address Majali sees you coming from, with an optional expiry. The policy page shows that address too, with the number of entries, so you can check before switching on.

The switch and the lockout guard

Allow admin access only from the network access list restricts the back office. When it is on:

  • Every request to the back office from an address not on the list is refused: sign-in, password reset, accepting an invitation and every admin page, on <company>.cloud.majali.app and on your own hosts alike. The refusal page shows the address Majali saw and says to ask your company’s Administrator.
  • The operations app, the owner space, the guest space and the website API are never restricted: field staff, owners, guests and your website’s visitors are outside the office.
  • You cannot lock yourself out. The switch cannot be turned on, and an entry cannot be changed or removed, if your own current address would then be excluded.
  • Every change asks for a fresh code and is recorded in the audit log with the list before and after.
  • Blocked attempts are counted per address and summarised to Administrators in a daily digest, never one email each. Repeated blocked sign-in attempts count towards the lockout.

If your company is locked out all the same (for example, the office changed its internet provider while every Administrator was away), Majali support lifts the restriction after checking the request out of band. Administrators receive an email saying it was lifted, and the change is recorded in the audit log.

The audit log

Open Settings > Security > Audit log. It is read-only for everyone, Administrators included, and open to roles that include reading it (Administrators and Managers by default). Each entry holds who did what, to which record, when, and from which address, kept as a keyed hash so that no address is stored in clear. Entries never hold names, emails or phone numbers.

Recorded events include: sign-ins and failed attempts, authenticator setup and reset, invitations, sign-ins turned off, role and permission changes, full contacts viewed, CSV and full exports, erasures, listings published and withdrawn, branding, domain, network and storage changes, payment and guest access changes, and every create, update and delete in the back office with the names of the fields that changed. Entries are kept for 12 months and then deleted.

Encryption and the key per company

Personal data is encrypted field by field: leads’ names, emails, phones and messages, team members’ contacts, guests’ and owners’ contacts, check-in notes and damage notes, authenticator secrets, the messages in the email log. Each company has encryption keys of its own, wrapped by a key that belongs to that company alone and is held apart from every other company’s. Nothing shared across companies can find a person: searching by email or phone works inside your company only.

Because the key is yours, closing the account destroys it, and from that moment every copy of your company’s data is unreadable, backups included (see Your data). Your data and its backups are kept in one hosting region (Abu Dhabi today) and never copied elsewhere. Passwords, invitation links and recovery codes are stored as hashes, never in clear, and logs and error reports have personal data and secrets removed before they are written.

Sessions

  • A session in the back office ends after 30 minutes without activity, and after 12 hours in any case.
  • A session in the operations app ends after 8 hours without activity, a shift in the field, and after 12 hours in any case.
  • Signing out ends the session on the server, not only in the browser.
  • A password change, a role change, a second-step reset or a sign-in turned off ends that person’s other sessions at once.
  • A session belongs to one company and one address: it never carries over to another company’s host.
  • An owner’s session in the owner space lasts 30 days; a guest’s session in the guest space 12 hours, or 30 days when they choose to be remembered.