Skip to main content
🔐 Enterprise-grade security

Trust & Security

Arabic Life is built with enterprise-grade security and tested rigorously to protect your family's data.

Quality Assurance

Tested at every level

Our automated test suite runs on every deployment across three real browser engines.

503Automated tests
303API endpoint tests
109Security tests
12WCAG accessibility tests
29Languages verified
3Browser engines

Chromium · Firefox · WebKit — all three engines, every commit

Security

Built secure by default

Security isn't an afterthought — it's part of every layer of the stack.

🛡️

Content Security Policy

Strict CSP headers on every response prevent XSS and injection attacks.

🔒

Row-Level Security

Every database table enforces RLS so users can only read and write their own data.

👶

COPPA-Compliant Children's Privacy

Parental consent required for users under 13. Kids Mode minimises data collection.

📌

Family PIN Protection

Child accounts are protected by a parent-set PIN for safe independent use.

🔑

OAuth — No Passwords Stored

Sign in via Google or Microsoft. We never store your password.

🌐

HTTPS Everywhere

All traffic is encrypted in transit. HTTP connections are rejected.

💾

Encrypted at Rest & In Transit

Data is encrypted both in the database and during transmission.

Accessibility

Learning without barriers

Arabic Life is designed to be usable by everyone, including learners with disabilities.

WCAG 2.1 AA Compliant

Meets international accessibility standards.

Keyboard Navigation

Every feature is reachable without a mouse.

Screen Reader Compatible

Tested with VoiceOver and NVDA.

Colour Contrast Verified

Minimum 4.5:1 ratio on all text.

ARIA Landmarks

Semantic structure on every page.

Data Privacy

Your data stays yours

We store your data in Australia, never sell it, and give you full control.

🇦🇺

Data stored in Australia (Supabase ap-southeast-2 — Sydney)

🇦🇺

No data sold to third parties — ever

🇦🇺

Parents control all child account data

🇦🇺

Right to deletion supported — accounts purged within 90 days of request

Read our full legal documents for complete details.