BF
BuildFlow
Reference document

The reference register of codes and standards
On what foundation was PZone ERP designed?

A comprehensive register of every standard, code, law, professional/governmental authority or cybersecurity framework that PZone ERP's design rests upon, with a statement of what the system actually embodies for each item.

PZone ERP — Standards, Codes & Regulatory Reference Register

01 Executive summary

PZone ERP was designed on a genuine standards base in Egyptian accounting and taxation, Egyptian labor, social insurance and data protection laws, FIDIC 2017 contracts, document control and quality (ISO 19650 / 9001), earned value (PMI) and dimensional take-off (NRM2/CESMM), with multi-tenant data isolation enforced in the database.

✓
The strongest things the system rests on (mandatory in the database): balanced double-entry with posted journal entries not editable · period locking · an immutable financial audit log · the A/B technical-approval gate before purchasing · money held by non-conformance NCR/RFI · enforcement of the governance approval chain by the appointee's account only · automatic RLS on every table · secured functions with a fixed search path · publishing gates with written confirmation.

02 Engineering and construction

What the system rests on in classification, measurement, estimating, quality, document control and cost control.

Standard / CodeAuthorityWhat the system actually embodies
CSI MasterFormatClassification of work sectionsCSI — Construction Specifications InstituteA section ← item hierarchy for classifying library items and activities and aggregating cost reports; 6000+ items shared globally, not copied per organization
FIDIC 2017 — Conditions of Contract for ConstructionSecond edition (Employer/Main contractor)FIDIC — International Federation of Consulting EngineersA full contract generator: agreement, contract data (Part A), letters of tender and acceptance, guarantees (performance/advance/retention/parent company/bid/payment), with the sub-clause number verbatim for each field (1.1.27 Defects Notification Period, 4.2, 5.1, 8.8 delay damages, 14.2/14.3 advance and retention, 19 insurance, 21 Dispute Avoidance/Adjudication Board DAAB)
ICC URDG 758Uniform Rules for Demand Guarantees 2010International Chamber of Commerce ICCGuarantee texts refer to it and require the demand for payment to be documented through a bank or a notary
ISO 19650Information management and Common Data Environment CDEISOCDE state constrained by rule (WIP/Shared/Published/Archived); document type and revision status are mandatory; a revision chain with supersession; transmittals with mandatory purpose/means; suitability codes S0–S4/A1/B1
Approval review codes A/B/C/DA approved · B approved with comments · C resubmit · D rejectedStandard consultant conventionA database constraint on {A,B,C,D}; a hard gate: no award of a request for quotation (and therefore no purchase order) for a material without an A or B approval
ISO 9001 — Non-conformance NCRDisposition, root cause and corrective/preventive action (§10.2)ISOSeverity (minor/major/critical), source and disposition (rework/repair/use-as-is/reject/regularize) are mandatory; the violated specification clause; the CAPA triad
ISO 9001 — Money held by qualityNCR/RFI hold the paymentISO + contractual conventionThe value of works under an open NCR or a blocking RFI is excluded from the approved value of the client's payment certificate; and approval/payment of the subcontractor's payment certificate is refused until closure
ISO 9001 — Material returns after NCRISOA return requires a purchase order, a catalog item and a quantity on the NCR, and is capped by the returnable quantity
ISO 9001 §8.4 — Control of external suppliersApproved vendor list AVL and qualificationISOAVL status constrained by rule (pending/approved/conditional/suspended/rejected); five qualification criteria (legal, financial, technical, track record, quality/safety); periodic performance evaluation; expiry of ISO 9001/45001 certificates
ISO 9001:2000 / ISO 9000In the entity qualification questionnaireISOTwo textual questions on the existence of a quality system and its certification
ISO 45001Occupational health and safetyISOA log of incidents/near-misses/injuries/illnesses, severity, lost days (≥0 mandatory), corrective action, linkage to the project; count indicators
ISO 30414Human capital reportingISOSelection of indicator families (workforce, turnover, training hours/cost, absence, safety)
PMI — Earned Value Management EVM"The standard PMI formula"PMI — Project Management InstituteBAC, EV (from actual site progress, quantity executed ÷ planned), AC (with no double-counting across manual/inventory/invoice), CPI=EV/AC, EAC=BAC/CPI, VAC; an S-curve and a CPI<1 alerts dashboard
NRM2 / CESMMDimensional take-off sheet (Dim sheet)RICS / ICEN×X (m), N×X×Y (m²), N×X×Y×Z (m³), negative "Ddt." deduction lines, repetition/density/waste factor, quantity locking by version (v1, v2…), an append-only progress log (correction by a new row not by editing, and deleting a measured row is refused)
CIOB / RICS practiceThe price build-up and preliminaries chainCIOB / RICSDirect + share of preliminaries = prime ← ×(1+overheads) ×(1+risk) ×(1+profit) = selling; a unit price to two decimals; 8 preliminaries categories; resources (materials/labor/equipment/subcontract); assumptions of 12% / 3% / 10%
IAS 2 — Capitalization of landed costLanded costIASBCustoms/freight/clearance/other are allocated proportionally by value across the purchase order lines and enter the unit cost
Three-way matchPurchase order / receipt / invoice, price variance ±5%Procurement conventionMatched = ordered = received = invoiced; a 5% price variance is flagged; a receipt rejected on inspection is excluded from inventory
Variation orders VOThe technical → commercial bridgeContractual conventionA technical change request ← a priced variation order with automatic numbering; only the approved one adjusts the contract value and the revenue
PMI — Schedule adherenceSPI / start & finish variance / baseline comparisonPMI — Project Management Institute · FIDIC 8.4Schedule baseline frozen at kickoff (re-baselined only by an approved EOT); planned % linear over duration; SPI = Σ(actual % × duration) ÷ Σ(planned % × duration); forecast finish at the actual progress rate; Δ in calendar days; contractual completion = time/date + approved extensions
SCL — Delay & Disruption Protocoldelay events / contractual liability / attributionSociety of Construction Law · FIDIC 8.4–8.5One delay event per task with a fixed cause code carrying its liability (employer: excusable & compensable · neutral: excusable, not compensable · contractor: LD exposure); attributed to a party from the parties register and a responsible person; evidence, recovery action and status; linked to the variation order when an EOT is claimed
FIDIC 2017 — 8.8 Delay Damagesexposure, relief and back-to-back chargeFIDIC · subcontract agreementsDaily damages = % of contract value or a fixed amount, capped; overrun = forecast − completion revised by approved EOT; relief from excusable days not yet converted into an EOT; subcontractor charged its attributed days × its agreement terms (ld_rate_pct_per_day, ld_cap_pct) never beyond the project overrun; required of the causer = remaining % ÷ days left
PMI — Critical path (CPM) and schedule compressioncrashing / fast-trackingPMI — Project Management InstituteFS/SS/FF/SF dependencies with lag; forward/backward pass on remaining durations, float, critical path; iterative crashing on the cheapest critical task (cost per saved day = daily cost × resource-type premium, capped cut, or a task-specific quote); fast-track FS→SS at half duration; net benefit = delay damages avoided − extra cost; resulting cash flow
Inspection requests IR/WIR and method statementsExecution conventionInspection type/result/status are mandatory; linking the inspection to an NCR; a method statement with a risk level and a review code A–D
Requests for information RFIExecution conventionMandatory priority, cost/time impact, linkage to a document, and the blocker holds a value until the answer
Handover / As-built fileProject closeout conventionA checklist (as-built drawings, operating manuals, warranties, test certificates, spare parts, training, snag list, compliance certificate) with a completion percentage
ISO 4217Currency codesISOA complete list; functional currency EGP; exchange rates per project
Abbreviations glossary (~500)ACI · ASTM · ASCE · AASHTO · ASHRAE · NFPA · NEC · IEEE · IEC · OSHA · EPA · CSI · EJCDC · AIA · ANSI · DIN · EN · BS · BIM/COBie/IFC/LOD · USGBC …Multiple authoritiesA linguistic reference translated into five languages explaining the abbreviations

03 Accounting, finance and taxation

The system's most standards-mature axis: double-entry accounting enforced in the database, IFRS/Egyptian standards named explicitly and implemented as engines, and genuine integration with the Egyptian Tax Authority.

Standard / LawAuthorityWhat the system actually embodies
Double-entry, trial balance and financial statementsAccounting principles—A line is debit or credit, not both (CHECK); posting requires ≥2 lines and total debit = credit ≠ 0, otherwise it is refused; a posted journal entry is not edited or deleted (correction by a reversing entry only); the account type is locked after posting; a unique sequential JE- number; a trial balance as a view; income statement/balance sheet/statement of changes in equity
Period locking and year-end closingRetained earnings—Posting to a closed month is refused by rule; the annual close closes revenues/expenses into 3200 and locks 12 months; reclosing is refused
IFRS 15 / Egyptian Accounting Standard 48Revenue by percentage of completion (cost-to-cost)IASB / Egyptian Standards BoardPercentage of completion = min(cost to date ÷ estimated cost EAC, 1); recognized revenue = contract value (base + approved variations) × the percentage; over/under-billing; CVR margin; a frozen monthly snapshot; the report footer states the standard explicitly
IAS 19 / Egyptian Standard 38Accrued leave provisionIASB / EASProvision = unused balance × daily wage (basic ÷ 30); a delta entry Dr 5510 / Cr 2540; not repeated
IAS 19 — End-of-service benefitsGulf engine + Egyptian policyIASB + Gulf labor systemsSA tiers (half a month/year ≤5 then a month), AE (21/30 days, cap 24 months), QA (21), OM (15 then a month); Saudi resignation factor; Egypt a month/year as policy; Dr 5800 / Cr 2700 and a settlement to the bank
IFRS 9Expected credit losses ECLIASBAgeing (current/30/60/90/+90) at rates 0.5/1/5/20/50%; Dr 5700 / Cr 1290 delta
IAS 16 / Egyptian Standard 10Fixed assets — straight-lineIASB / EAS(cost − scrap) ÷ life in months, a full month; acquisition Dr 1500, depreciation Dr 5600 / Cr 1600, disposal with gain/loss 4200
IAS 12Deferred taxIASBTemporary differences between book and tax depreciation; a tax rate of 22.5% (Egypt); reducing-balance tax depreciation 25% adjustable per asset; Dr 5900 / Cr 2800
IAS 21The effects of changes in foreign exchange ratesIASBFunctional currency EGP; currencies EGP/USD/EUR/GBP/SAR/AED/KWD; realized exchange difference on settlement to 4300; revaluation of open balances (2900/1295)
IAS 7 / Egyptian Standard 4Statement of cash flows — indirectIASB / EASClassification by the account code prefix: 11xx cash, 15xx/16xx investing, 24xx loans and 31xx capital financing, the rest operating
IAS 2 / Egyptian Standard 2Perpetual inventoryIASB / EASReceipt Dr 1400 / Cr 2110 (GR-IR); issue to the project Dr 5410 / Cr 1400; return to the supplier; capitalization of landed cost
Chart of accounts "simplified Egyptian style"—60+ accounts (1000–5900) with system keys (cash, bank, receivables, retention, withholding under account, VAT inputs/outputs/settlement, employee advances, rental deposits, inventory, assets/accumulated depreciation, payables, GR-IR, client advances, subcontract, payroll and insurance and taxes payable, leave/end-of-service provisions, deferred tax, capital, retained earnings, contract revenue, exchange differences, expenses…) created at first use and edited freely, with self-healing of missing keys
Auto-posting engineOperational event ← journal entrySystem design~40 event types (approval/payment of a supplier invoice, receipt, issue, return, supplier advance, subcontract cost/payment, payment-certificate revenue/collection, retention release, payroll accrual/payment, employee advances, leave/end-of-service/debt provisions, training, medical, communications, logistics, custody, monthly rent, rental-deposit settlement, assets, VAT return, deferred tax, revaluation, deferrals, recurring, opening balances, closing) — one entry per event (source_type + source_id) not repeated, and correction by reversing then reposting; provisions on a "required level" logic (delta)
Budget and project cost EAC and cost centersCost control practiceETC = max(budget − actual, open commitments); EAC = actual + ETC; the variance; two analytical dimensions (project/cost center); purchase-order commitments; bank reconciliation; a cash forecast — monthly over 6 months or weekly over 13 weeks, company-wide or per project, charted (assumptions of 60/30/28 days); receivables claims
Egyptian value-added tax 14%Outputs and inputs and a monthly returnEgyptian Tax AuthorityOutputs on the current works value of the payment certificate (2210); inputs on supplier invoices (1230); a monthly return with a settlement Dr 2210 / Cr 1230 / Cr 2211 not repeated; a tax register for export
Withholding under account 1%ContractingEgyptian Tax AuthorityWithheld from the amount due to the client and recorded as a prepaid asset (1220); exported to the Tax Authority with code T4/W010
Stamp duty and contracting insurance—Two fields in the settings with a value of 0
E-invoice systemVersion 1.0 document · OAuth2 · CAdES signatureEgyptian Tax Authority (ETA)preprod/production environments with the Authority's official endpoints; OAuth2 client_credentials; a document of type I version 1.0 with an issuer/receiver of type B; tax codes T1/V009 (VAT) and T4/W010 (withholding); rounding to 5 decimals; a serialization algorithm for the CAdES signature; a readiness check (registration number, activity code, address, EGS codes); UUID/status registration; sending from the server only (the secret does not leave it) and for approved/paid payment certificates only
The company's legal identityTax number and commercial registerTax Authority / commercial register (as fields)The owner alone sets them (RAISE); a match of the tax number with registered parties generates a verification request approved by the platform administrator; the tax number is the parties' identity key and the source of the RIN received in the e-invoice
Immutable financial audit logAudit trailAudit practice (SOX-style)A SECURITY DEFINER trigger records every insert/update/delete on entries, accounts and supplier invoices (who, what before/after, when, the actor's email from the JWT); read for the owner/administrator; no write policies so it is not edited from the application
Approvals and segregation of dutiesSegregation of dutiesCOSO-styleAmount limits for manual entries and a separate disbursement authorization for suppliers; recording the submitter/approver; a hard check in disbursement custody: the approver ≠ the submitter

04 Payroll, labor and social insurance

Law / SystemAuthorityWhat the system actually embodies
Egyptian Labor Law 14/2025Ministry of Labor (Egypt)A written contract form (permanent/fixed/seasonal type, probation period, hours, leave, notice period); a high alert "an employee without an active contract — the law mandates a written contract"; alerts for expiry of the contract/probation/documents/work permit; annual leave of 21 days; a health and safety section
Social Insurance Law 148/2019National Social Insurance AuthorityAn insurance number and a subscription date; a "no insurance" alert; an insurance wage with a minimum/maximum (2000–12600); an employee share of 11% and an employer share of 18.75%; accrual entries 2510
Payroll income tax — progressive bracketsEgyptian Tax AuthorityPersonal exemption 20,000; marginal annual brackets 0/10/15/20/22.5/25/27.5% on (gross − employee insurance)×12 then ÷12; a bracket editor per organization
Gulf labor systems — end-of-service benefits and leaveSaudi Arabia Arts. 84–85 and 109 · UAE · Qatar · OmanGulf labor ministriesA data-driven register per jurisdiction; end-of-service tiers; the Saudi resignation factor (0 / ⅓ / ⅔ / full); statutory leave scaling with service (SA 21→30, QA 21→28, AE/OM 30)
GOSI · GPSSA · GRSIA · PASISocial insurance of Saudi Arabia/UAE/Qatar/OmanGulf social insurance institutionsCitizen/expatriate rates and wage limits per country (e.g. SA citizen 9.75%/11.75%, expatriate 0/2%, limit 1500–45000); zero income tax; nationality classification
Egyptian leave catalogLabor LawAnnual 21 (feeds the provision) · sick · casual 7 · unpaid · maternity
Personal Data Protection Law 151/2020Personal Data Protection Center (Egypt)Cited as a justification for RLS policies: the employee file and its sensitive documents (national ID image, the contract) are read by the administrator or the data subject only; the medical by a named delegate; payroll for the owner/administrator for all operations
SHRM BASKSociety for Human Resource Management (SHRM)A design reference for the records and performance model
ISO 30414 · ISO 45001ISOHuman capital indicators and a safety log

05 Legal, contractual and governance

ItemReference / AuthorityWhat the system actually embodies
FIDIC 2017 — Legal clauses1.4 governing law and language · 1.15 limitation of liability · 17.2(d) forces of nature · 19 insurance · 21 DAABFIDICFields for the governing law, the governing language and the language of correspondence, the contractor's limitation of liability, forces-of-nature risks, insurance limits (professional liability, fitness for purpose), a Dispute Avoidance Board with an appointing entity "the FIDIC President"
Subcontractor contractsContractual conventionA retention percentage; the net amount due a generated column (claimed − retention); agreement and payment-certificate statuses are mandatory; an NCR/RFI gate prevents approval/payment
Client payment certificates: retention, advance and deductions"The usual Egyptian arrangement" (a comment)The current = cumulative − previous − retained; retention 5%; VAT on the current; withholding under account and the advance and others are deducted; retention release on the client/subcontract side is mandatory; retention ageing 90/180/365
Supplier advances and their applicationPracticeOn approving the supplier invoice its advance is applied automatically: its own order first then the oldest; reversible
Tender registerPracticeMandatory statuses (Bidding/Submitted/Won/Lost/Cancelled); converting a win into a project; the project phase is mandatory (tender/execution/closed); freezing the baseline before kickoff
Contractor qualification questionnaireRegistration/classification certificate "in the local federation" · the authorized signatory · the capital · a banking disclosure authorization · consortiumsThe Egyptian Federation for Construction and Building Contractors (implicitly)A full self-qualification form: works executed by year, executives, proposed team, equipment, subcontractors, similar projects, a quality system and ISO questions, an HSE manual, a banking disclosure with authority, "all data in Arabic"
The governance module — 26 form typesBoard resolutions · minutes · committee formation/plans · periodic reports · resolution follow-up · delegations (Art. 17) · performance evaluation (Art. 32) · conflict of interest (Chapter 9) · confidentiality undertaking NDA · related parties · onboarding · opportunity registration (Art. 11) · initiatives · RACI · payment schedules · sub-alliance agreements · incentives (Arts. 48/51–53/55) · founders' contributions and rights · individual/entity evaluation · organizational structureThe corporate governance charter and company bylaws (internal)Numbered corporate forms with a draft/final status, along with the texts of confidentiality and conflict-of-interest undertakings (adherence to the "governance charter and professional conduct rules"), incentive eligibility conditions, and statutory onboarding steps; defined boards, committees and an authority hierarchy
The authority matrix P/R/T/A/E/M and enforcement of the approval chain"Appendix (1) of the executive governance manual"The company governance manualA hierarchy (general assembly ← board ← executive board ← committees); 4 default, editable permission groups; a derived approval chain; RLS: no approval except by the account appointed to that authority, one approval per step, and no signature attributed to another account
E-signature and QR-code verification—The QR = a public verification link /verify/g/<uuid> with an unguessable identifier; the public function exposes metadata only (the reference, the title, the status, the approval chain, the signatures) not the resolution text; the generated contracts use a capability token independent of the internal identifier; the signatures are PNG images attributed to their owner's account under an RLS constraint. SHA‑256 content seal (Level A): each signature is sealed with a SHA‑256 hash of the document content at the moment of signing (computed inside the database via pgcrypto and fixed by the insert trigger), and the verification page recomputes and compares it, thus revealing any later modification to the content (tamper‑evidence: sealed/the seal is broken). This is still not a signature with an accredited PKI certificate nor an accredited timestamp (RFC 3161), and it does not seal the PDF file image at the binary level
Legal identity and verificationTax number / commercial registerThe owner alone sets them; the platform administrator alone approves the verification; the verified data are auto-filled into the contracts
Invitations and rolesAccess governanceEvery invitation with a "viewer" role under a CHECK constraint; role change from an allowed list only; the owner is protected from promotion/demotion/termination
Legal rental attachmentsA copy of the contract · proof of ownership/power of attorney · a civil defense license · an insurance document · an inspection reportCivil Defense (a license type)The attachment types are mandatory; the critical ones (civil defense, insurance) have a red alert on expiry; insurance, disbursement and contract statuses are mandatory; "cancelled by decision" requires a reason and who decided; an owner with a national ID and a delegate (power of attorney); a signed inspection is locked by a trigger
The source and intellectual property—Modules ported from a previous system and re-scoped

06 Cybersecurity and data protection

The code does not cite any security framework by name; therefore every actual control was aligned with the recognized frameworks (OWASP Top 10/ASVS, ISO/IEC 27001, NIST SP 800-53, COSO, Law 151/2020, GDPR principles, and Supabase practices). The alignment is by design — it does not mean certification.

ControlThe framework it aligns withThe actual mechanism
Multi-tenant isolation via RLS + an auto-enablement triggerOWASP A01 · ISO 27001 A.9.4.1 · NIST AC-3/AC-4Every new table in public has RLS enabled automatically by a DDL trigger; belongs_to_my_org compares against the active organization with a membership check (tampering with active_org_id does not help)
Role-based permissions within the tenantNIST AC-6 · ISO 27001 A.9.2.3Read = any member; write = administrator/manager/owner; delete = administrator/owner; the platform administrator overrides; two documented fixes (the active organization's role, and lax task policies that allowed a viewer to write)
Prevention of self role escalationCWE-269 · OWASP A01The user does not change their role/status; a role-change function with an allowed list that protects the owner (two documented and fixed production vulnerabilities); a CHECK on the roles
Sealing the tenant key from the serverCWE-639org_id is populated from the active organization before insertion and is checked by the insert policy
SECURITY DEFINER functions with a fixed search pathCWE-426 · Supabase checksSET search_path on every definer function; a retroactive fix of three "search path injection" functions
Revoking EXECUTE from PUBLIC and anon (4 documented rounds)NIST AC-6 · Supabase checkA documented lesson: revoking from anon alone is not enough — it must be from PUBLIC; trigger functions are revoked from everyone
security_invoker viewsCWE-1220Views do not bypass RLS
Authorization inside functions (~225 RAISE guards)OWASP A01 · ASVS V4"Not logged in" + a role check for each sensitive function (verification, invitation revocation, party deletion, company creation…)
No raw SQL (injection)OWASP A03 · CWE-89The client is via PostgREST exclusively; migrations use format(%I) on literal lists
Authentication and sessionOWASP A07 · ASVS V2/V3 · NIST IA-2Email/password + Google OAuth + recovery; a one-hour JWT with refresh-token rotation; login rate limits from the platform; account-enumeration mitigation
Account status gateISO 27001 A.9.2.1 · NIST AC-2Approved/pending/rejected with separate screens
Immutable audit logISO 27001 A.12.4 · NIST AU-9 · SOX-styleA definer trigger that is not bypassed; no write policies
Append-only logs (site progress)ISO 27001 A.12.4 · ISO 19650Correction by a new row; deleting a measured row is refused (RESTRICT)
Attributed approvals and signatures (non-repudiation)NIST AU-10 · ISO 27001 A.6.1.2Approval by the appointee's account only; the signature by its owner's account; a personal signatures vault with no edit policy
Financial segregation of dutiesCOSO · NIST AC-5 · SOX 404Submitter/approver recorded with amount limits; a hard check in custody
Secrets managementOWASP A02 · NIST IA-5 · ISO 27001 A.9.4.3No embedded credentials; boot fails without environment variables (no silent fallback); the anon key for the browser only; Tax Authority/AI/email secrets in edge functions; ignoring .env and SQL dumps; no keys in the repository (verified)
Edge function authorizationOWASP A01/A07 · NIST SC-5JWT identity + organization membership + document status; a scheduled secret for reports; rejecting non-POST; size/count limits for the AI
CI/CD: restricted deployment and confirmed destructive operationsISO 27001 A.12.1.2/A.12.1.4 · NIST CM-3/CM-5Migrations are deployed only when their path changes and with a branch↔environment binding (no secret crossover); syncing/rebuilding staging requires typing a code (SYNC-STAGING / REBUILD-STAGING) with an automatic backup of the branch; the secrets in GitHub only
Testing gatesISO 27001 A.14.2.8 · NIST SA-11An E2E check required on every PR to main + nightly; units on the services
Storage: private buckets and short signed linksISO 27001 A.10.1 · NIST SC-8Drawings and rental attachments with 60-second links, take-off 300 seconds; bucket policies with a <org>/ or <user>/ path; a fix for a public file-listing leak
Validation of uploaded filesASVS V12 · CWE-434Allowed-type lists and limits of 2–20 MB on the client; a 50 MB server-side ceiling
XSSOWASP A03 · CWE-79React's default escaping; escapeHtml on every cell in the export; ~14 direct-HTML positions all escaped; no eval
Data integrityNIST SI-10Allowed lists, non-negativity, cross conditions, unique per tenant, deliberate delete semantics (CASCADE/SET NULL/RESTRICT), a 1000-row ceiling per request
Personal data protection in RLSLaw 151/2020 · GDPR Arts. 5(1)(f)/32 · ISO 27001 A.9.4.1The administrator or the data subject; the medical by a named delegate; payroll for the owner/administrator; the Tax Authority secret does not reach the rest of the members
The right to erasure (company + individual)GDPR Art. 17 · Law 151/2020Company deletion: the owner only + typing the company name to confirm; an orderly teardown with a termination log. Individual account deletion: written confirmation, a clean resignation from all companies, protection of company owners, and deletion of the auth account with the service role
Transport and clientNIST SC-8 · OWASP A05HTTPS exclusively (no http:// in the code); the service worker excludes Supabase from caching
The unauthenticated public surfaceGDPR Art. 5(1)(c) · OWASP A01Three paths (a shortlisted file, governance verification, contract verification); governance verification with minimal exposure; the contracts with a capability token
The platform administratorISO 27001 A.9.2.3 · CWE-798A flag on the profile that overrides RLS and manages the add-ons and verification
The software supply chainOWASP A06 · NIST SA-12 · ISO 27001 A.12.6.1A committed lock file + npm ci; up-to-date dependencies
Operational documentation and recoveryISO 27001 A.12.1.1 · A.17 · NIST CP-9A full re-provisioning guide (migrations, functions, secrets, Auth setup, the storage policies vulnerability, data migration)

07 Register of governmental and professional authorities

Every authority whose footprint appears in the system, its actual role, and the degree of reliance on it. "Implicit" means the authority is not named in the code but its product (a law/number/license) is used.

🏛 Governmental and regulatory authorities

  • Egyptian Tax Authority (ETA) — VAT 14%, withholding under account 1%, payroll income tax, income tax 22.5% (deferred), the e-invoice system (actual integration), a tax register for returns
  • National Social Insurance Authority — Law 148/2019, insurance number, wage rates and limits (its name as an abbreviation only; no integration)
  • Egyptian Ministry of Labor — Labor Law 14/2025 (written contract, probation, leave, safety)
  • Personal Data Protection Center — Law 151/2020 as a justification for access policies
  • Civil Defense — a license as a type of critical attachment for the leased units (as a type) / the authority is implicit
  • Commercial register / tax card — legal identity fields verified by the platform administrator
  • The Egyptian Federation for Construction and Building Contractors — "registration/classification certificate in the local federation" in the qualification questionnaire, implicit
  • Saudi Ministry of Human Resources — Labor System Arts. 84–85, 109; GOSI/SANED
  • GPSSA (UAE) · GRSIA (Qatar) · PASI (Oman) — insurance rates and end-of-service benefits

📐 Professional authorities and standards

  • IASB (IFRS/IAS) + Egyptian Accounting Standards Board (EAS) — 15/48, 19/38, 16/10, 12, 21, 2, 7/4, IFRS 9
  • FIDIC — Conditions of Contract for Construction 2017 as a contracts generator
  • ICC — URDG 758 in the guarantee texts
  • ISO — 19650, 9001, 45001, 30414, 4217
  • CSI — MasterFormat
  • PMI — earned value (the cost side)
  • RICS / ICE — NRM2 / CESMM (the take-off sheet)
  • CIOB — price build-up practice
  • SHRM — BASK as a design reference
  • ~500 authorities in the abbreviations glossary (ACI, ASTM, ASCE, AASHTO, ASHRAE, NFPA, NEC, IEEE, IEC, OSHA, EPA, EJCDC, AIA, ANSI, DIN, EN, BS, USGBC…) a linguistic reference only
  • Security frameworks (OWASP, ISO 27001, NIST 800-53, COSO, Supabase practices) — alignment by design, not certification
  • Deloitte / KPMG — mentioned as an aspiration of "presentability to auditors" in a migration header

08 Confidence statement — what can be said with confidence

The user's confidence is built on what can be proven from the code. Here is what can rightly be said with confidence about PZone ERP:

✓ Rightly said (backed by the code)

  • "The accounting was designed in accordance with IFRS and the Egyptian standards (48/IFRS 15, 38/IAS 19, 10/IAS 16, IAS 12, IAS 21, IAS 2, 4/IAS 7, IFRS 9) with double-entry enforced in the database, closed periods, an immutable audit log, and segregation of duties."
  • "It meets the requirements of the Egyptian Tax Authority: VAT 14%, withholding under account, and actual integration with the e-invoice system (version 1.0 document) without retaining your signing key."
  • "It invokes Labor Law 14/2025, Social Insurance 148/2019 and Data Protection 151/2020 in the HR model and the access policies."
  • "It generates FIDIC 2017 contracts with the clause reference, controls documents in accordance with ISO 19650, and manages quality in accordance with ISO 9001 (NCR/CAPA/approved vendor list) with gates that actually hold money."
  • "It computes earned value in accordance with PMI (the cost side) and adopts a dimensional take-off on the NRM2/CESMM pattern."
  • "Each company's data isolation is enforced in the database on every table automatically, with secured functions, secrets outside the code, and deployment behind confirmation gates."

Applied security and privacy measures