IbaadU Trust & Security Centre

IbaadU uses account controls, vendor document review, structured PRQ workflows and platform security measures to support safer B2B sourcing across the Middle East.

KYC Verification Process

Vendor accounts must complete the applicable document-review workflow before receiving an approved status. Approval records the platform review performed at that time; buyers should still conduct transaction-specific due diligence.

Step 1 — Business Registration

Vendors submit their trade licence, commercial registration, or equivalent business document from their country of operation.

Step 2 — Identity Verification

An authorised representative provides an accepted identity document for review with the submitted business records.

Step 3 — Business Details Review

Submitted company, contact and operating-country details are checked for completeness and consistency.

Step 4 — Ongoing Monitoring

Accounts may be reviewed again when documents expire, important details change, or risk signals require follow-up.

Buyer accounts: Email confirmation and profile controls apply to procurer accounts. Additional checks may be requested according to transaction risk or partner requirements.

Payment & Transaction Coordination

IbaadU supports structured payment coordination workflows where enabled for a transaction. Buyers and vendors should confirm milestone terms, payment method, delivery evidence, and dispute handling before proceeding.

  1. Agree commercial terms, including specifications, milestones, inspection and delivery evidence.
  2. Confirm the payment provider and beneficiary details through an authorised business contact.
  3. Record fulfilment evidence and keep transaction communications in the platform where available.
  4. Escalate concerns promptly through IbaadU support and the applicable payment or legal channel.
Important: Escrow or third-party payment protection is available only when explicitly confirmed for a specific transaction. IbaadU is not a bank and this page is not a financial guarantee.

Platform Security

IbaadU applies layered application, hosting and database controls. Security reduces risk but cannot guarantee that any internet service will never experience an incident.

Encrypted Transport

HTTPS is enforced and HSTS instructs compatible browsers to use encrypted connections.

Security Headers

Content-Security-Policy, frame, content-type, referrer and permissions headers are configured at the web-server layer.

Upload Controls

Upload workflows restrict accepted file types and sizes. Sensitive documents should remain in access-controlled storage.

Availability Controls

Hosting protections, request limits and monitoring should be maintained and tested as platform traffic grows.

Backup & Recovery

Database and hosting backup settings are maintained with the relevant service providers and should be recovery-tested regularly.

Responsible Disclosure

Report suspected vulnerabilities to admin@ibaadu.com and include enough detail for investigation. See our security.txt.

Data Privacy

IbaadU is committed to the responsible handling of all user and business data in accordance with applicable UAE data protection laws and international best practices.

  • Personal and business data is collected only for the purposes of facilitating B2B trade and platform operations.
  • Data is never sold to third parties. Marketing communications require explicit opt-in.
  • KYC documents must be stored with access controls and retained only for documented business or legal needs.
  • Users may request data access, correction, or deletion via admin@ibaadu.com.
  • Full details in our Privacy Policy.

Compliance Reference Framework

These references guide product and operating controls. They do not claim certification, legal approval or independent attestation unless supporting evidence is published.

ISO 27001 Information-security control reference; not a certification claim
UAE PDPL Privacy-law reference for data handling and user rights
AML/CFT Risk-based checks may apply through regulated payment and trade partners
PCI-DSS Aligned Card data should be handled only by an appropriately compliant payment provider

Dispute Resolution

IbaadU provides a support path for reporting transaction concerns. Available remedies depend on the contract, payment provider, evidence and applicable law.

  1. Report the concern: Contact support promptly with the order or PRQ reference.
  2. Preserve evidence: Keep specifications, quotations, payment records, shipping records, photos and communications.
  3. Counterparty review: IbaadU may request information from both parties and document the platform record.
  4. External escalation: Payment-provider, mediation, insurer or legal channels may be required.
  5. Outcome: Any refund, release or remedy depends on the agreed transaction terms and authorised provider.

IbaadU support does not replace independent legal advice, a court, an arbitrator or a regulated payment provider.

Contact the Security Team

If you have discovered a security vulnerability, have a compliance question, or wish to report a suspicious vendor or transaction, please contact us directly:

Security Vulnerabilities
admin@ibaadu.com
Response within 48 hours. See our security.txt.
Privacy & Data Requests
admin@ibaadu.com
Data access, correction, or deletion requests.
Trade Compliance
compliance@ibaadu.com
KYC queries, AML concerns, dispute escalations.
General Support
support@ibaadu.com
+971 4 832 2447
Sun–Thu, 09:00–18:00 GST