Account & Authentication Policy
This Account & Authentication Policy establishes the rules and practices governing ARZAQ INSIGHTS accounts and the authentication services used to access services within the ARZAQ INSIGHTS ecosystem.
1. Purpose
The purpose of this policy is to establish a secure, consistent, and controlled authentication experience while maintaining a clear separation between central account services and product-specific operational data.
2. Scope
This policy applies to the central ARZAQ INSIGHTS account system, including:
This policy does not govern the internal authentication or authorization rules that an individual product may implement for its own product-specific functions.
3. Central Account Model
ARZAQ INSIGHTS operates a centralized account model. A user creates an ARZAQ account once and may use that account to authenticate with participating products without creating a separate authentication identity for every product.
4. Account Identity & Multi-Account Isolation
Each ARZAQ account represents a distinct account identity. A user may have multiple ARZAQ accounts and may sign into multiple accounts on the same device.
Accounts remain separate even when accessed from the same device. Information belonging to one ARZAQ account is not automatically merged with another ARZAQ account. Account switching allows users to move between separately authenticated accounts seamlessly without repeated logouts.
5. Account Registration
Users may create an ARZAQ account using supported registration flows. Information required includes: Name, Email address, Phone number, Gender, Recovery email address, and authentication credentials.
Users are responsible for providing accurate information. ARZAQ INSIGHTS may implement verification mechanisms to confirm ownership of an email address or phone number.
6. Authentication Methods
7. Authentication Security Controls
Security controls include cryptographic password hashing, 2FA, passkeys, secure session management, login monitoring, authentication logging, IP/device anomaly detection, and failed attempt rate limiting.
8. Password Requirements
Users must use unique passwords, avoid predictable strings, avoid reusing passwords across services, and immediately update credentials upon suspected compromise.
9. Two-Factor Authentication
Users should maintain control over their second-factor devices. If lost, the official account recovery process must be followed.
10. Passkey & Biometric Security
ARZAQ INSIGHTS does not collect or store your underlying biometric data (fingerprint, Face ID, etc.). Biometric verification happens locally on your device hardware in accordance with FIDO2 / WebAuthn standards.
11. Account Recovery
Account recovery methods include verified recovery email, phone verification, and pre-configured factors. ARZAQ INSIGHTS may delay or deny recovery requests if ownership cannot be satisfactorily established.
12. Recovery Email
A recovery email is used for ownership verification, security alerts, and recovery communications. Users must ensure continuous control over their recovery email account.
13. Login and Security Records
We maintain records of login/logout history, successful and failed authentications, IP addresses, client devices, session durations, 2FA/Passkey events, and security setting modifications.
14. User Access to Account Activity
Users can view their active sessions, recent logins, device types, and download security logs directly from their Central ARZAQ Account dashboard.
15. Account Switching
Users can maintain an active multi-account pool on a single browser. Users must verify the active profile before initiating actions inside connected products.
16. Product Authentication & 17. Separation From Product Data
ARZAQ INSIGHTS identifies and authenticates who the user is. Individual products determine product-specific roles (e.g. Admin, Manager, Member) and maintain their own databases.
18. Session Management
Central sessions include secure expiration, renewal tokens, remote logout, and session invalidation triggers upon password changes.
19. Suspicious or Unauthorized Activity
Upon detecting anomaly events (repeated failed attempts, credential stuffing, impossible travel logins), ARZAQ INSIGHTS may enforce re-authentication, challenge with 2FA, invalidate active sessions, or temporarily restrict authentication.
20. Account Security Responsibilities
Users are responsible for safeguarding credentials, devices, and OTP codes. Never share magic links or 2FA codes with third parties.
21. Compromised Accounts
22. Security Changes & 23. Account Deletion
Users may initiate permanent deletion directly through the account dashboard. Deletion permanently revokes authentication tokens, subject to required financial/audit record retentions.
24. Multiple Accounts & 25. Authentication Availability
ARZAQ INSIGHTS aims for high availability across central authentication endpoints, but may occasionally undergo scheduled maintenance or emergency security mitigation.
26. Policy Updates & 27. Contact Information
28. Core Security Principle Summary
ARZAQ INSIGHTS manages identity and authentication. Participating platforms manage their own operational records and authorizations.