FAQ
Frequently asked questions
Frequently asked questions about Qarfina Platform include common topics such as account management, API access, integration workflows, and system requirements.
Security & Access Management
Platform Security Architecture
What security measures protect my platform session?
The platform uses industry-standard encryption for data in transit and at rest. Sessions are secured with time-limited tokens and automatic logout after periods of inactivity. We recommend enabling two-factor authentication in your account settings for an additional layer of protection.
How do I manage API keys for integrations?
API keys are generated and revoked from the 'Developer Tools' section of your account settings. You can set specific permissions and IP whitelists for each key to limit access scope. It is best practice to rotate keys periodically and never share them in public repositories or unsecured channels.
What should I do if I suspect unauthorized access?
Immediately change your password and revoke all active sessions and API keys from your security settings. Do not attempt to troubleshoot credential issues via email replies; instead, verify your identity through the official support portal at Qarfina · Support Center. We do not request passwords or 2FA codes via email.
Does the platform support Single Sign-On (SSO) for enterprise teams?
SSO integration is available for enterprise accounts and can be configured via SAML 2.0 or OIDC protocols. Contact your account manager or send a request to [email protected] to initiate the setup process. Enterprise security reviews are conducted prior to SSO activation.
How are platform vulnerabilities reported?
We maintain a responsible disclosure program for security researchers. Please report any potential vulnerabilities via our dedicated security contact form linked in the footer. We do not use [email protected] for security reports; ensure you use the correct channel to ensure timely review.