Skip to main content

Overview

Security is a core value at Iqra AI, viewed as an Amanah (Trust) between the platform and its users. This guide covers security best practices for self-hosted deployments, helping you protect user data, maintain compliance, and prevent security incidents.
While the Iqra AI codebase is secure by design, proper deployment and configuration are your responsibility. Security failures typically occur due to misconfiguration, not code vulnerabilities.

Security principles

Iqra AI follows these security principles:
  1. Defense in depth - Multiple layers of security controls
  2. Least privilege - Minimum permissions required for operation
  3. Secure by default - New resources start in the most secure state
  4. Transparency - Clear security policies and incident response

Network security

Firewall configuration

Only expose necessary ports to the public internet:
1

Allow HTTP/HTTPS

Ports 80 and 443 for web traffic:
2

Allow RTP for voice

UDP ports 10000-20000 for real-time audio:
3

Block database ports

Ensure MongoDB and Redis are NOT accessible publicly:
4

Enable firewall

These firewall rules are documented in the Security Policy at SECURITY.md:58.

Internal network isolation

Use Docker networks or VPCs to isolate services:
This ensures databases are only accessible from application containers.

TLS/SSL configuration

HTTPS is mandatory. WebRTC and browser microphone access will fail over insecure HTTP connections.
Use a reverse proxy with valid SSL certificates:

Authentication and authorization

Change default credentials

This is the most critical security step. Failure to change default credentials is the #1 cause of security breaches in self-hosted deployments.
Immediately change the default admin credentials:
Generate a strong password:

API secret tokens

Generate cryptographically secure API keys for internal service communication:
Configure in environment variables or secrets management:
Rotate API keys quarterly and whenever an employee with access leaves the organization.

Server API keys

Each regional server requires a unique API key (minimum 32 characters):
Never reuse API keys across servers or regions. Each server must have a unique key as documented in RegionManager.cs:297.

Data protection

Encryption at rest

Encrypt sensitive data stored in MongoDB:
1

Enable MongoDB encryption

Configure MongoDB with encryption at rest:
2

Generate encryption key

3

Restart MongoDB

Encryption in transit

All network communication should use TLS:
  • Frontend ↔ Backend: HTTPS (enforced by reverse proxy)
  • Backend ↔ MongoDB: MongoDB TLS connection
  • Backend ↔ Redis: Redis TLS/SSL mode
  • Backend ↔ LLM APIs: HTTPS (built into integrations)

Secure sessions (PCI-DSS compliance)

Iqra AI includes a Secure Sessions feature for handling sensitive data like credit card numbers:
The Secure Sessions system creates a “clean room” for sensitive data:
  1. Conversation enters secure mode via script action
  2. Audio/DTMF input is processed by deterministic engine only
  3. AI receives validation results, never raw sensitive data
  4. Data is masked in logs and recordings
  5. Session exits secure mode after data collection
This ensures compliance with PCI-DSS and other data privacy standards.
Implement secure sessions for:
  • Payment card information
  • Social security numbers
  • Health information (PHI)
  • Any regulated data
See the Secure Sessions documentation for implementation details.

Access control

Principle of least privilege

Grant minimum necessary permissions: MongoDB user permissions:
Redis ACL:

SSH hardening

Secure SSH access to servers:
Use SSH keys instead of passwords:

Compliance

Data residency

For deployments requiring data to remain in specific jurisdictions:
1

Deploy region in required country

Create a region in the country with data residency requirements:
2

Configure regional S3

Use object storage physically located in that country:
3

Pin organization to region

Configure organization settings to ensure data never leaves the region.
Iqra AI Enterprise supports dedicated infrastructure for GCC nations and other regions with strict data residency requirements. Contact sales for details.

GDPR compliance

For European deployments:
  1. Data minimization: Only collect necessary conversation data
  2. Right to erasure: Implement data deletion workflows
  3. Data portability: Provide export functionality for user data
  4. Consent management: Track user consent for data processing
  5. Privacy by design: Enable secure sessions for sensitive data

Audit logging

Maintain audit logs for compliance:
Store audit logs separately from application data and retain for compliance periods (typically 1-7 years).

Vulnerability management

Reporting vulnerabilities

If you discover a security vulnerability:
DO NOT report security vulnerabilities via GitHub Issues. This could expose your deployment and others to risk.
1

Email security team

Send details to security@iqra.bot
2

Include required information

  • Type of issue (XSS, Injection, RCE, etc.)
  • Proof of concept or reproduction steps
  • Impact assessment
3

Wait for acknowledgment

You’ll receive acknowledgment within 48 hours
4

Maintain confidentiality

Do not disclose publicly until a fix is released
Full details in the Security Policy.

Supported versions

Update policy

Stay current with security updates:
  1. Monitor releases: Watch the GitHub repository for security releases
  2. Test updates: Validate in staging environment first
  3. Apply promptly: Deploy security patches within 7 days
  4. Document changes: Maintain change log for compliance audits

Incident response

Incident response plan

Prepare for security incidents before they occur:
1

Detection

Monitor for security events:
  • Failed authentication attempts
  • Unusual access patterns
  • System resource anomalies
  • Database connection from unexpected IPs
2

Containment

Immediate actions:
  • Isolate affected systems
  • Revoke compromised credentials
  • Enable maintenance mode if needed
3

Investigation

Analyze the incident:
  • Review audit logs
  • Check system logs
  • Identify attack vector
  • Assess scope of compromise
4

Remediation

Fix the vulnerability:
  • Apply security patches
  • Update configurations
  • Rotate credentials
5

Recovery

Restore normal operations:
  • Validate all systems are secure
  • Re-enable disabled services
  • Monitor for recurrence
6

Post-incident review

Learn and improve:
  • Document timeline
  • Identify root cause
  • Update security procedures

Data breach notification

If a data breach affects user data:
  1. Assess impact: Determine what data was exposed
  2. Notify users: Within 72 hours per GDPR requirements
  3. Notify authorities: If required by local regulations
  4. Provide support: Offer credit monitoring or other remediation
  5. Document incident: Create detailed post-mortem
Iqra Cloud (SaaS) follows the same process, as documented in SECURITY.md:65.

Security checklist

Before going to production:
  • Changed default admin credentials
  • Generated unique API keys for all servers (≥32 chars)
  • Configured firewall (allow 80/443/10000-20000, block 27017/6379)
  • Enabled HTTPS with valid SSL certificates
  • Configured MongoDB authentication and encryption
  • Configured Redis authentication
  • Isolated databases on internal network only
  • Disabled password-based SSH authentication
  • Implemented audit logging
  • Documented incident response plan
  • Set up security monitoring and alerts
  • Reviewed and tested backup/recovery procedures

Best practices summary

Do’s

  1. Change all defaults - Never use default passwords or keys
  2. Use strong encryption - TLS for transit, encryption for rest
  3. Apply least privilege - Minimum permissions required
  4. Monitor continuously - Log and alert on security events
  5. Update regularly - Apply security patches promptly
  6. Test backups - Verify recovery procedures work

Don’ts

  1. Don’t expose databases - MongoDB and Redis must be internal only
  2. Don’t reuse credentials - Unique keys per server/region
  3. Don’t skip HTTPS - Required for WebRTC functionality
  4. Don’t ignore alerts - Investigate all security events
  5. Don’t report publicly - Use security@iqra.bot for vulnerabilities

Next steps

Multi-region

Deploy secure infrastructure across multiple regions

Monitoring

Set up security monitoring and alerting