Security

Security, from the gate to the database.

MeetPass is built defence-in-depth: every layer — the credential, the gateway, the application and the data — is hardened, encrypted and auditable.

Defence in depth

A layered model, from the gate to the database.

01

Credential security

Tamper-evident, single-use QR credentials with identity verification before issue.

02

Gateway verification

Every scan is verified at the gateway — online or offline for air-gapped sites.

03

Encryption & keys

Data encrypted at rest and in transit, with keys you control on your own servers.

04

Access control

Role-based access and least privilege, with privileged-member separation by default.

Encryption & key management

You hold the keys.

Records are encrypted at rest and in transit. In on-premise deployments, encryption keys never leave your environment — so no third party can read your data.

  • Encrypted at rest and in transit
  • Customer-held keys on-premise
  • No third-party decryption path
Encryption / key management illustration
Audit & logging

Tamper-evident audit trail.

Every issue, scan and entry is logged immutably and retrievable for security reviews, investigations and compliance — with full search across sites.

  • Immutable entry logs
  • Full-text search over every record
  • Export for compliance reviews
admin.meetpass.com
On-site now 248
Pending 17
Today 1,204
VisitorA. RahmanCleared
VehiclePlate 4421At gate
MeetingBoard roomActive
For government

Built to sit inside a national assurance policy.

Qatar's National Information Assurance Policy v2.0, owned by the National Cyber Security Agency, classifies every government information asset and scales its controls accordingly. MeetPass was designed to be deployable at each level rather than certified for one and hoped for at the rest.

NIA classification — controls tighten as the class rises
Public Open information

Standard controls. Visitor records still written to the immutable log.

Limited Access Internal only

Role-based access, directory authentication, retention windows enforced.

Restricted Damage if disclosed

Segregated records, dual authorisation on overrides, full session audit.

Secret Serious damage

Air-gapped deployment, cleared operators only, no external connectivity of any kind.

Classification names follow the NIA v2.0 scheme published by the NCSA. Applicable controls and assurance level are determined by your own risk assessment, not by us. Read the policy.

National identity integration

The NIA policy expects government systems to authenticate against Qatar's national identity infrastructure. MeetPass reads and verifies the QID at registration and can authenticate staff against your directory rather than holding a second identity store.

Classification-aware records

Meeting and visitor records inherit a classification at creation. Restricted and Secret sessions are segregated, and access to them is gated on clearance rather than on role alone.

Evidence for the annual audit

NIA compliance is audited annually by a certification body. The immutable log exports the entry, approval, override and retention evidence an assessor asks for, rather than requiring it to be assembled by hand.

Deployed inside the boundary

For classified environments the whole platform runs on your infrastructure — private cloud, on-premise, or fully air-gapped with signed watchlist bundles imported on your own schedule.

For enterprise

Your visitor book is an ISO 27001 control.

Physical entry is not adjacent to information security — it is Annex A 7.2 of the standard itself. And it is the control your assessor observes first, because they walk through your lobby before they open a single document. A paper ledger is a finding waiting to happen.

ControlWhat the standard asks forWhat MeetPass gives the assessor
A.7.1 Physical security perimeters Sites, gates and zones modelled in the platform, with which pass types may cross which perimeter.
A.7.2 Physical entry Identity verified before arrival, entry authorised by a named host, every crossing scanned and logged.
A.7.3 Securing offices, rooms and facilities Room-level restrictions, privileged sessions and zone rules enforced from the same credential.
A.5.15 Access control Role-based access with least privilege, reviewed and reassignable without touching the record.
A.5.28 Collection of evidence A tamper-evident audit trail that an investigator or assessor can export without your team rebuilding it.
A.8.15 Logging Every request, approval, scan, override and export written with actor, action and timestamp.
What you can hand an auditor on the day
  • Every entry and exit for any date range, by site, gate, host or individual
  • The approval chain behind each visit — who authorised it and when
  • Every override, with both approvers named under dual authorisation
  • Retention and deletion events, showing the policy actually ran
  • Access reviews — who held which role over the period under audit
Across every pass

The same controls, whatever the credential.

Security is not a module you switch on for the sensitive sites. Every pass type inherits the same verification, the same authorisation chain and the same immutable record — only the specifics differ.

Meeting Pass

Classification set at creation · privileged sessions segregated · signed MOM with signature audit · minutes distribution logged

Visitor Pass

QID/passport verification before issue · watchlist screening at request · signed QR validated offline · exit and overstay recorded

Car Pass

Plate bound to the credential · barrier validation logged · bay assignment and release on the same record

Residential Pass

No documents held at the gate · tenant-authorised entry · per-unit approval rules · full retrieval by name, number or date

Event Pass

Capacity enforced at registration · zone restrictions per attendee type · turnstile validation · live occupancy for safety

One credential layer means one audit trail. There is no second system to reconcile, and no gap between them for something to fall through.

Where your data lives

Residency, on your terms.

For most buyers this is the first question and the shortest conversation: the records generated by MeetPass live wherever your policy says they must, and nowhere else.

Qatar data residency

Hosted in-country on GCP Doha or Azure Qatar Central — or entirely on your own infrastructure. Records stay in the jurisdiction you nominate.

Your infrastructure, your keys

On-premise deployments hold their own encryption keys. No third party, including us, can read your data.

Retention you control

Configurable retention and deletion per record class, with the expiry events themselves written to the audit trail.

Air-gapped where required

A fully disconnected installation with signed watchlist bundles imported on your own schedule.

Compliance

Aligned with the standards that matter.

MeetPass is architected to support regional data-residency mandates and recognised security practices.

Certified Information security management — certified at Source Code Tech Solutions, the company that builds and operates MeetPass.
Certified AI management system — covering the AI tier and how it is governed.
Certified ISO 9001:2015 Quality management across delivery and support.
Live Qatar PDPPL Consent, retention and data-subject controls built into the platform and configurable per deployment.
Live Data residency In-country hosting or on-premise deployment, with jurisdiction and retention under your control.
Deployable Qatar NIA v2.0 Architected to be deployed at each NIA classification level, up to air-gapped for Secret.
Validated Government validation Cleared an on-premise security review in a live Ministry of Interior proof of concept.
Alignment track Platform ISO 27001 Certification of the MeetPass platform in its own right is on the roadmap — today the certification is held at company level.
Alignment track SOC 2 Trust-services controls mapped; formal attestation targeted as the platform scales.

We publish only what we hold. Where a standard is in progress it is labelled an alignment track — never presented as a certification. Certifications marked Certified are held by Source Code Tech Solutions, the company that builds and supports MeetPass; certification of your own management system remains yours to hold. Full architecture and compliance documentation is available under NDA during due diligence.

Security FAQ

Answers for your security team.

Yes. For the most sensitive sites, MeetPass deploys with no external network dependency — credential verification works offline at the gate.

Only the roles you authorise. Access is role-based with least privilege, and privileged actions are separated and logged.

Passes are single-use and tamper-evident, verified cryptographically at the gateway — a screenshot or copy will not clear the gate.

Yes — full security and architecture documentation is available for evaluation under NDA. Arrange it through a briefing.

On infrastructure you nominate — in-country on GCP Doha or Azure Qatar Central, in your own private cloud, or entirely on your own servers. On-premise deployments hold their own encryption keys, so no third party, including us, can read the data.

Every entry and exit for any date range by site, gate, host or individual; the approval chain behind each visit; every override with both approvers named; retention and deletion events; and access reviews for the period under audit.

Review the architecture with our security team.

Arrange a confidential briefing — including full documentation under NDA.