01 Executive summary
PZone ERP was designed on a genuine standards base in Egyptian accounting and taxation, Egyptian labor, social insurance and data protection laws, FIDIC 2017 contracts, document control and quality (ISO 19650 / 9001), earned value (PMI) and dimensional take-off (NRM2/CESMM), with multi-tenant data isolation enforced in the database.
02 Engineering and construction
What the system rests on in classification, measurement, estimating, quality, document control and cost control.
| Standard / Code | Authority | What the system actually embodies |
|---|---|---|
| CSI MasterFormatClassification of work sections | CSI — Construction Specifications Institute | A section ← item hierarchy for classifying library items and activities and aggregating cost reports; 6000+ items shared globally, not copied per organization |
| FIDIC 2017 — Conditions of Contract for ConstructionSecond edition (Employer/Main contractor) | FIDIC — International Federation of Consulting Engineers | A full contract generator: agreement, contract data (Part A), letters of tender and acceptance, guarantees (performance/advance/retention/parent company/bid/payment), with the sub-clause number verbatim for each field (1.1.27 Defects Notification Period, 4.2, 5.1, 8.8 delay damages, 14.2/14.3 advance and retention, 19 insurance, 21 Dispute Avoidance/Adjudication Board DAAB) |
| ICC URDG 758Uniform Rules for Demand Guarantees 2010 | International Chamber of Commerce ICC | Guarantee texts refer to it and require the demand for payment to be documented through a bank or a notary |
| ISO 19650Information management and Common Data Environment CDE | ISO | CDE state constrained by rule (WIP/Shared/Published/Archived); document type and revision status are mandatory; a revision chain with supersession; transmittals with mandatory purpose/means; suitability codes S0–S4/A1/B1 |
| Approval review codes A/B/C/DA approved · B approved with comments · C resubmit · D rejected | Standard consultant convention | A database constraint on {A,B,C,D}; a hard gate: no award of a request for quotation (and therefore no purchase order) for a material without an A or B approval |
| ISO 9001 — Non-conformance NCRDisposition, root cause and corrective/preventive action (§10.2) | ISO | Severity (minor/major/critical), source and disposition (rework/repair/use-as-is/reject/regularize) are mandatory; the violated specification clause; the CAPA triad |
| ISO 9001 — Money held by qualityNCR/RFI hold the payment | ISO + contractual convention | The value of works under an open NCR or a blocking RFI is excluded from the approved value of the client's payment certificate; and approval/payment of the subcontractor's payment certificate is refused until closure |
| ISO 9001 — Material returns after NCR | ISO | A return requires a purchase order, a catalog item and a quantity on the NCR, and is capped by the returnable quantity |
| ISO 9001 §8.4 — Control of external suppliersApproved vendor list AVL and qualification | ISO | AVL status constrained by rule (pending/approved/conditional/suspended/rejected); five qualification criteria (legal, financial, technical, track record, quality/safety); periodic performance evaluation; expiry of ISO 9001/45001 certificates |
| ISO 9001:2000 / ISO 9000In the entity qualification questionnaire | ISO | Two textual questions on the existence of a quality system and its certification |
| ISO 45001Occupational health and safety | ISO | A log of incidents/near-misses/injuries/illnesses, severity, lost days (≥0 mandatory), corrective action, linkage to the project; count indicators |
| ISO 30414Human capital reporting | ISO | Selection of indicator families (workforce, turnover, training hours/cost, absence, safety) |
| PMI — Earned Value Management EVM"The standard PMI formula" | PMI — Project Management Institute | BAC, EV (from actual site progress, quantity executed ÷ planned), AC (with no double-counting across manual/inventory/invoice), CPI=EV/AC, EAC=BAC/CPI, VAC; an S-curve and a CPI<1 alerts dashboard |
| NRM2 / CESMMDimensional take-off sheet (Dim sheet) | RICS / ICE | N×X (m), N×X×Y (m²), N×X×Y×Z (m³), negative "Ddt." deduction lines, repetition/density/waste factor, quantity locking by version (v1, v2…), an append-only progress log (correction by a new row not by editing, and deleting a measured row is refused) |
| CIOB / RICS practiceThe price build-up and preliminaries chain | CIOB / RICS | Direct + share of preliminaries = prime ← ×(1+overheads) ×(1+risk) ×(1+profit) = selling; a unit price to two decimals; 8 preliminaries categories; resources (materials/labor/equipment/subcontract); assumptions of 12% / 3% / 10% |
| IAS 2 — Capitalization of landed costLanded cost | IASB | Customs/freight/clearance/other are allocated proportionally by value across the purchase order lines and enter the unit cost |
| Three-way matchPurchase order / receipt / invoice, price variance ±5% | Procurement convention | Matched = ordered = received = invoiced; a 5% price variance is flagged; a receipt rejected on inspection is excluded from inventory |
| Variation orders VOThe technical → commercial bridge | Contractual convention | A technical change request ← a priced variation order with automatic numbering; only the approved one adjusts the contract value and the revenue |
| PMI — Schedule adherenceSPI / start & finish variance / baseline comparison | PMI — Project Management Institute · FIDIC 8.4 | Schedule baseline frozen at kickoff (re-baselined only by an approved EOT); planned % linear over duration; SPI = Σ(actual % × duration) ÷ Σ(planned % × duration); forecast finish at the actual progress rate; Δ in calendar days; contractual completion = time/date + approved extensions |
| SCL — Delay & Disruption Protocoldelay events / contractual liability / attribution | Society of Construction Law · FIDIC 8.4–8.5 | One delay event per task with a fixed cause code carrying its liability (employer: excusable & compensable · neutral: excusable, not compensable · contractor: LD exposure); attributed to a party from the parties register and a responsible person; evidence, recovery action and status; linked to the variation order when an EOT is claimed |
| FIDIC 2017 — 8.8 Delay Damagesexposure, relief and back-to-back charge | FIDIC · subcontract agreements | Daily damages = % of contract value or a fixed amount, capped; overrun = forecast − completion revised by approved EOT; relief from excusable days not yet converted into an EOT; subcontractor charged its attributed days × its agreement terms (ld_rate_pct_per_day, ld_cap_pct) never beyond the project overrun; required of the causer = remaining % ÷ days left |
| PMI — Critical path (CPM) and schedule compressioncrashing / fast-tracking | PMI — Project Management Institute | FS/SS/FF/SF dependencies with lag; forward/backward pass on remaining durations, float, critical path; iterative crashing on the cheapest critical task (cost per saved day = daily cost × resource-type premium, capped cut, or a task-specific quote); fast-track FS→SS at half duration; net benefit = delay damages avoided − extra cost; resulting cash flow |
| Inspection requests IR/WIR and method statements | Execution convention | Inspection type/result/status are mandatory; linking the inspection to an NCR; a method statement with a risk level and a review code A–D |
| Requests for information RFI | Execution convention | Mandatory priority, cost/time impact, linkage to a document, and the blocker holds a value until the answer |
| Handover / As-built file | Project closeout convention | A checklist (as-built drawings, operating manuals, warranties, test certificates, spare parts, training, snag list, compliance certificate) with a completion percentage |
| ISO 4217Currency codes | ISO | A complete list; functional currency EGP; exchange rates per project |
| Abbreviations glossary (~500)ACI · ASTM · ASCE · AASHTO · ASHRAE · NFPA · NEC · IEEE · IEC · OSHA · EPA · CSI · EJCDC · AIA · ANSI · DIN · EN · BS · BIM/COBie/IFC/LOD · USGBC … | Multiple authorities | A linguistic reference translated into five languages explaining the abbreviations |
03 Accounting, finance and taxation
The system's most standards-mature axis: double-entry accounting enforced in the database, IFRS/Egyptian standards named explicitly and implemented as engines, and genuine integration with the Egyptian Tax Authority.
| Standard / Law | Authority | What the system actually embodies |
|---|---|---|
| Double-entry, trial balance and financial statementsAccounting principles | — | A line is debit or credit, not both (CHECK); posting requires ≥2 lines and total debit = credit ≠ 0, otherwise it is refused; a posted journal entry is not edited or deleted (correction by a reversing entry only); the account type is locked after posting; a unique sequential JE- number; a trial balance as a view; income statement/balance sheet/statement of changes in equity |
| Period locking and year-end closingRetained earnings | — | Posting to a closed month is refused by rule; the annual close closes revenues/expenses into 3200 and locks 12 months; reclosing is refused |
| IFRS 15 / Egyptian Accounting Standard 48Revenue by percentage of completion (cost-to-cost) | IASB / Egyptian Standards Board | Percentage of completion = min(cost to date ÷ estimated cost EAC, 1); recognized revenue = contract value (base + approved variations) × the percentage; over/under-billing; CVR margin; a frozen monthly snapshot; the report footer states the standard explicitly |
| IAS 19 / Egyptian Standard 38Accrued leave provision | IASB / EAS | Provision = unused balance × daily wage (basic ÷ 30); a delta entry Dr 5510 / Cr 2540; not repeated |
| IAS 19 — End-of-service benefitsGulf engine + Egyptian policy | IASB + Gulf labor systems | SA tiers (half a month/year ≤5 then a month), AE (21/30 days, cap 24 months), QA (21), OM (15 then a month); Saudi resignation factor; Egypt a month/year as policy; Dr 5800 / Cr 2700 and a settlement to the bank |
| IFRS 9Expected credit losses ECL | IASB | Ageing (current/30/60/90/+90) at rates 0.5/1/5/20/50%; Dr 5700 / Cr 1290 delta |
| IAS 16 / Egyptian Standard 10Fixed assets — straight-line | IASB / EAS | (cost − scrap) ÷ life in months, a full month; acquisition Dr 1500, depreciation Dr 5600 / Cr 1600, disposal with gain/loss 4200 |
| IAS 12Deferred tax | IASB | Temporary differences between book and tax depreciation; a tax rate of 22.5% (Egypt); reducing-balance tax depreciation 25% adjustable per asset; Dr 5900 / Cr 2800 |
| IAS 21The effects of changes in foreign exchange rates | IASB | Functional currency EGP; currencies EGP/USD/EUR/GBP/SAR/AED/KWD; realized exchange difference on settlement to 4300; revaluation of open balances (2900/1295) |
| IAS 7 / Egyptian Standard 4Statement of cash flows — indirect | IASB / EAS | Classification by the account code prefix: 11xx cash, 15xx/16xx investing, 24xx loans and 31xx capital financing, the rest operating |
| IAS 2 / Egyptian Standard 2Perpetual inventory | IASB / EAS | Receipt Dr 1400 / Cr 2110 (GR-IR); issue to the project Dr 5410 / Cr 1400; return to the supplier; capitalization of landed cost |
| Chart of accounts "simplified Egyptian style" | — | 60+ accounts (1000–5900) with system keys (cash, bank, receivables, retention, withholding under account, VAT inputs/outputs/settlement, employee advances, rental deposits, inventory, assets/accumulated depreciation, payables, GR-IR, client advances, subcontract, payroll and insurance and taxes payable, leave/end-of-service provisions, deferred tax, capital, retained earnings, contract revenue, exchange differences, expenses…) created at first use and edited freely, with self-healing of missing keys |
| Auto-posting engineOperational event ← journal entry | System design | ~40 event types (approval/payment of a supplier invoice, receipt, issue, return, supplier advance, subcontract cost/payment, payment-certificate revenue/collection, retention release, payroll accrual/payment, employee advances, leave/end-of-service/debt provisions, training, medical, communications, logistics, custody, monthly rent, rental-deposit settlement, assets, VAT return, deferred tax, revaluation, deferrals, recurring, opening balances, closing) — one entry per event (source_type + source_id) not repeated, and correction by reversing then reposting; provisions on a "required level" logic (delta) |
| Budget and project cost EAC and cost centers | Cost control practice | ETC = max(budget − actual, open commitments); EAC = actual + ETC; the variance; two analytical dimensions (project/cost center); purchase-order commitments; bank reconciliation; a cash forecast — monthly over 6 months or weekly over 13 weeks, company-wide or per project, charted (assumptions of 60/30/28 days); receivables claims |
| Egyptian value-added tax 14%Outputs and inputs and a monthly return | Egyptian Tax Authority | Outputs on the current works value of the payment certificate (2210); inputs on supplier invoices (1230); a monthly return with a settlement Dr 2210 / Cr 1230 / Cr 2211 not repeated; a tax register for export |
| Withholding under account 1%Contracting | Egyptian Tax Authority | Withheld from the amount due to the client and recorded as a prepaid asset (1220); exported to the Tax Authority with code T4/W010 |
| Stamp duty and contracting insurance | — | Two fields in the settings with a value of 0 |
| E-invoice systemVersion 1.0 document · OAuth2 · CAdES signature | Egyptian Tax Authority (ETA) | preprod/production environments with the Authority's official endpoints; OAuth2 client_credentials; a document of type I version 1.0 with an issuer/receiver of type B; tax codes T1/V009 (VAT) and T4/W010 (withholding); rounding to 5 decimals; a serialization algorithm for the CAdES signature; a readiness check (registration number, activity code, address, EGS codes); UUID/status registration; sending from the server only (the secret does not leave it) and for approved/paid payment certificates only |
| The company's legal identityTax number and commercial register | Tax Authority / commercial register (as fields) | The owner alone sets them (RAISE); a match of the tax number with registered parties generates a verification request approved by the platform administrator; the tax number is the parties' identity key and the source of the RIN received in the e-invoice |
| Immutable financial audit logAudit trail | Audit practice (SOX-style) | A SECURITY DEFINER trigger records every insert/update/delete on entries, accounts and supplier invoices (who, what before/after, when, the actor's email from the JWT); read for the owner/administrator; no write policies so it is not edited from the application |
| Approvals and segregation of dutiesSegregation of duties | COSO-style | Amount limits for manual entries and a separate disbursement authorization for suppliers; recording the submitter/approver; a hard check in disbursement custody: the approver ≠ the submitter |
04 Payroll, labor and social insurance
| Law / System | Authority | What the system actually embodies |
|---|---|---|
| Egyptian Labor Law 14/2025 | Ministry of Labor (Egypt) | A written contract form (permanent/fixed/seasonal type, probation period, hours, leave, notice period); a high alert "an employee without an active contract — the law mandates a written contract"; alerts for expiry of the contract/probation/documents/work permit; annual leave of 21 days; a health and safety section |
| Social Insurance Law 148/2019 | National Social Insurance Authority | An insurance number and a subscription date; a "no insurance" alert; an insurance wage with a minimum/maximum (2000–12600); an employee share of 11% and an employer share of 18.75%; accrual entries 2510 |
| Payroll income tax — progressive brackets | Egyptian Tax Authority | Personal exemption 20,000; marginal annual brackets 0/10/15/20/22.5/25/27.5% on (gross − employee insurance)×12 then ÷12; a bracket editor per organization |
| Gulf labor systems — end-of-service benefits and leaveSaudi Arabia Arts. 84–85 and 109 · UAE · Qatar · Oman | Gulf labor ministries | A data-driven register per jurisdiction; end-of-service tiers; the Saudi resignation factor (0 / ⅓ / ⅔ / full); statutory leave scaling with service (SA 21→30, QA 21→28, AE/OM 30) |
| GOSI · GPSSA · GRSIA · PASISocial insurance of Saudi Arabia/UAE/Qatar/Oman | Gulf social insurance institutions | Citizen/expatriate rates and wage limits per country (e.g. SA citizen 9.75%/11.75%, expatriate 0/2%, limit 1500–45000); zero income tax; nationality classification |
| Egyptian leave catalog | Labor Law | Annual 21 (feeds the provision) · sick · casual 7 · unpaid · maternity |
| Personal Data Protection Law 151/2020 | Personal Data Protection Center (Egypt) | Cited as a justification for RLS policies: the employee file and its sensitive documents (national ID image, the contract) are read by the administrator or the data subject only; the medical by a named delegate; payroll for the owner/administrator for all operations |
| SHRM BASK | Society for Human Resource Management (SHRM) | A design reference for the records and performance model |
| ISO 30414 · ISO 45001 | ISO | Human capital indicators and a safety log |
05 Legal, contractual and governance
| Item | Reference / Authority | What the system actually embodies |
|---|---|---|
| FIDIC 2017 — Legal clauses1.4 governing law and language · 1.15 limitation of liability · 17.2(d) forces of nature · 19 insurance · 21 DAAB | FIDIC | Fields for the governing law, the governing language and the language of correspondence, the contractor's limitation of liability, forces-of-nature risks, insurance limits (professional liability, fitness for purpose), a Dispute Avoidance Board with an appointing entity "the FIDIC President" |
| Subcontractor contracts | Contractual convention | A retention percentage; the net amount due a generated column (claimed − retention); agreement and payment-certificate statuses are mandatory; an NCR/RFI gate prevents approval/payment |
| Client payment certificates: retention, advance and deductions | "The usual Egyptian arrangement" (a comment) | The current = cumulative − previous − retained; retention 5%; VAT on the current; withholding under account and the advance and others are deducted; retention release on the client/subcontract side is mandatory; retention ageing 90/180/365 |
| Supplier advances and their application | Practice | On approving the supplier invoice its advance is applied automatically: its own order first then the oldest; reversible |
| Tender register | Practice | Mandatory statuses (Bidding/Submitted/Won/Lost/Cancelled); converting a win into a project; the project phase is mandatory (tender/execution/closed); freezing the baseline before kickoff |
| Contractor qualification questionnaireRegistration/classification certificate "in the local federation" · the authorized signatory · the capital · a banking disclosure authorization · consortiums | The Egyptian Federation for Construction and Building Contractors (implicitly) | A full self-qualification form: works executed by year, executives, proposed team, equipment, subcontractors, similar projects, a quality system and ISO questions, an HSE manual, a banking disclosure with authority, "all data in Arabic" |
| The governance module — 26 form typesBoard resolutions · minutes · committee formation/plans · periodic reports · resolution follow-up · delegations (Art. 17) · performance evaluation (Art. 32) · conflict of interest (Chapter 9) · confidentiality undertaking NDA · related parties · onboarding · opportunity registration (Art. 11) · initiatives · RACI · payment schedules · sub-alliance agreements · incentives (Arts. 48/51–53/55) · founders' contributions and rights · individual/entity evaluation · organizational structure | The corporate governance charter and company bylaws (internal) | Numbered corporate forms with a draft/final status, along with the texts of confidentiality and conflict-of-interest undertakings (adherence to the "governance charter and professional conduct rules"), incentive eligibility conditions, and statutory onboarding steps; defined boards, committees and an authority hierarchy |
| The authority matrix P/R/T/A/E/M and enforcement of the approval chain"Appendix (1) of the executive governance manual" | The company governance manual | A hierarchy (general assembly ← board ← executive board ← committees); 4 default, editable permission groups; a derived approval chain; RLS: no approval except by the account appointed to that authority, one approval per step, and no signature attributed to another account |
| E-signature and QR-code verification | — | The QR = a public verification link /verify/g/<uuid> with an unguessable identifier; the public function exposes metadata only (the reference, the title, the status, the approval chain, the signatures) not the resolution text; the generated contracts use a capability token independent of the internal identifier; the signatures are PNG images attributed to their owner's account under an RLS constraint. SHA‑256 content seal (Level A): each signature is sealed with a SHA‑256 hash of the document content at the moment of signing (computed inside the database via pgcrypto and fixed by the insert trigger), and the verification page recomputes and compares it, thus revealing any later modification to the content (tamper‑evidence: sealed/the seal is broken). This is still not a signature with an accredited PKI certificate nor an accredited timestamp (RFC 3161), and it does not seal the PDF file image at the binary level |
| Legal identity and verification | Tax number / commercial register | The owner alone sets them; the platform administrator alone approves the verification; the verified data are auto-filled into the contracts |
| Invitations and roles | Access governance | Every invitation with a "viewer" role under a CHECK constraint; role change from an allowed list only; the owner is protected from promotion/demotion/termination |
| Legal rental attachmentsA copy of the contract · proof of ownership/power of attorney · a civil defense license · an insurance document · an inspection report | Civil Defense (a license type) | The attachment types are mandatory; the critical ones (civil defense, insurance) have a red alert on expiry; insurance, disbursement and contract statuses are mandatory; "cancelled by decision" requires a reason and who decided; an owner with a national ID and a delegate (power of attorney); a signed inspection is locked by a trigger |
| The source and intellectual property | — | Modules ported from a previous system and re-scoped |
06 Cybersecurity and data protection
The code does not cite any security framework by name; therefore every actual control was aligned with the recognized frameworks (OWASP Top 10/ASVS, ISO/IEC 27001, NIST SP 800-53, COSO, Law 151/2020, GDPR principles, and Supabase practices). The alignment is by design — it does not mean certification.
| Control | The framework it aligns with | The actual mechanism |
|---|---|---|
| Multi-tenant isolation via RLS + an auto-enablement trigger | OWASP A01 · ISO 27001 A.9.4.1 · NIST AC-3/AC-4 | Every new table in public has RLS enabled automatically by a DDL trigger; belongs_to_my_org compares against the active organization with a membership check (tampering with active_org_id does not help) |
| Role-based permissions within the tenant | NIST AC-6 · ISO 27001 A.9.2.3 | Read = any member; write = administrator/manager/owner; delete = administrator/owner; the platform administrator overrides; two documented fixes (the active organization's role, and lax task policies that allowed a viewer to write) |
| Prevention of self role escalation | CWE-269 · OWASP A01 | The user does not change their role/status; a role-change function with an allowed list that protects the owner (two documented and fixed production vulnerabilities); a CHECK on the roles |
| Sealing the tenant key from the server | CWE-639 | org_id is populated from the active organization before insertion and is checked by the insert policy |
| SECURITY DEFINER functions with a fixed search path | CWE-426 · Supabase checks | SET search_path on every definer function; a retroactive fix of three "search path injection" functions |
| Revoking EXECUTE from PUBLIC and anon (4 documented rounds) | NIST AC-6 · Supabase check | A documented lesson: revoking from anon alone is not enough — it must be from PUBLIC; trigger functions are revoked from everyone |
| security_invoker views | CWE-1220 | Views do not bypass RLS |
| Authorization inside functions (~225 RAISE guards) | OWASP A01 · ASVS V4 | "Not logged in" + a role check for each sensitive function (verification, invitation revocation, party deletion, company creation…) |
| No raw SQL (injection) | OWASP A03 · CWE-89 | The client is via PostgREST exclusively; migrations use format(%I) on literal lists |
| Authentication and session | OWASP A07 · ASVS V2/V3 · NIST IA-2 | Email/password + Google OAuth + recovery; a one-hour JWT with refresh-token rotation; login rate limits from the platform; account-enumeration mitigation |
| Account status gate | ISO 27001 A.9.2.1 · NIST AC-2 | Approved/pending/rejected with separate screens |
| Immutable audit log | ISO 27001 A.12.4 · NIST AU-9 · SOX-style | A definer trigger that is not bypassed; no write policies |
| Append-only logs (site progress) | ISO 27001 A.12.4 · ISO 19650 | Correction by a new row; deleting a measured row is refused (RESTRICT) |
| Attributed approvals and signatures (non-repudiation) | NIST AU-10 · ISO 27001 A.6.1.2 | Approval by the appointee's account only; the signature by its owner's account; a personal signatures vault with no edit policy |
| Financial segregation of duties | COSO · NIST AC-5 · SOX 404 | Submitter/approver recorded with amount limits; a hard check in custody |
| Secrets management | OWASP A02 · NIST IA-5 · ISO 27001 A.9.4.3 | No embedded credentials; boot fails without environment variables (no silent fallback); the anon key for the browser only; Tax Authority/AI/email secrets in edge functions; ignoring .env and SQL dumps; no keys in the repository (verified) |
| Edge function authorization | OWASP A01/A07 · NIST SC-5 | JWT identity + organization membership + document status; a scheduled secret for reports; rejecting non-POST; size/count limits for the AI |
| CI/CD: restricted deployment and confirmed destructive operations | ISO 27001 A.12.1.2/A.12.1.4 · NIST CM-3/CM-5 | Migrations are deployed only when their path changes and with a branch↔environment binding (no secret crossover); syncing/rebuilding staging requires typing a code (SYNC-STAGING / REBUILD-STAGING) with an automatic backup of the branch; the secrets in GitHub only |
| Testing gates | ISO 27001 A.14.2.8 · NIST SA-11 | An E2E check required on every PR to main + nightly; units on the services |
| Storage: private buckets and short signed links | ISO 27001 A.10.1 · NIST SC-8 | Drawings and rental attachments with 60-second links, take-off 300 seconds; bucket policies with a <org>/ or <user>/ path; a fix for a public file-listing leak |
| Validation of uploaded files | ASVS V12 · CWE-434 | Allowed-type lists and limits of 2–20 MB on the client; a 50 MB server-side ceiling |
| XSS | OWASP A03 · CWE-79 | React's default escaping; escapeHtml on every cell in the export; ~14 direct-HTML positions all escaped; no eval |
| Data integrity | NIST SI-10 | Allowed lists, non-negativity, cross conditions, unique per tenant, deliberate delete semantics (CASCADE/SET NULL/RESTRICT), a 1000-row ceiling per request |
| Personal data protection in RLS | Law 151/2020 · GDPR Arts. 5(1)(f)/32 · ISO 27001 A.9.4.1 | The administrator or the data subject; the medical by a named delegate; payroll for the owner/administrator; the Tax Authority secret does not reach the rest of the members |
| The right to erasure (company + individual) | GDPR Art. 17 · Law 151/2020 | Company deletion: the owner only + typing the company name to confirm; an orderly teardown with a termination log. Individual account deletion: written confirmation, a clean resignation from all companies, protection of company owners, and deletion of the auth account with the service role |
| Transport and client | NIST SC-8 · OWASP A05 | HTTPS exclusively (no http:// in the code); the service worker excludes Supabase from caching |
| The unauthenticated public surface | GDPR Art. 5(1)(c) · OWASP A01 | Three paths (a shortlisted file, governance verification, contract verification); governance verification with minimal exposure; the contracts with a capability token |
| The platform administrator | ISO 27001 A.9.2.3 · CWE-798 | A flag on the profile that overrides RLS and manages the add-ons and verification |
| The software supply chain | OWASP A06 · NIST SA-12 · ISO 27001 A.12.6.1 | A committed lock file + npm ci; up-to-date dependencies |
| Operational documentation and recovery | ISO 27001 A.12.1.1 · A.17 · NIST CP-9 | A full re-provisioning guide (migrations, functions, secrets, Auth setup, the storage policies vulnerability, data migration) |
07 Register of governmental and professional authorities
Every authority whose footprint appears in the system, its actual role, and the degree of reliance on it. "Implicit" means the authority is not named in the code but its product (a law/number/license) is used.
🏛 Governmental and regulatory authorities
- Egyptian Tax Authority (ETA) — VAT 14%, withholding under account 1%, payroll income tax, income tax 22.5% (deferred), the e-invoice system (actual integration), a tax register for returns
- National Social Insurance Authority — Law 148/2019, insurance number, wage rates and limits (its name as an abbreviation only; no integration)
- Egyptian Ministry of Labor — Labor Law 14/2025 (written contract, probation, leave, safety)
- Personal Data Protection Center — Law 151/2020 as a justification for access policies
- Civil Defense — a license as a type of critical attachment for the leased units (as a type) / the authority is implicit
- Commercial register / tax card — legal identity fields verified by the platform administrator
- The Egyptian Federation for Construction and Building Contractors — "registration/classification certificate in the local federation" in the qualification questionnaire, implicit
- Saudi Ministry of Human Resources — Labor System Arts. 84–85, 109; GOSI/SANED
- GPSSA (UAE) · GRSIA (Qatar) · PASI (Oman) — insurance rates and end-of-service benefits
📐 Professional authorities and standards
- IASB (IFRS/IAS) + Egyptian Accounting Standards Board (EAS) — 15/48, 19/38, 16/10, 12, 21, 2, 7/4, IFRS 9
- FIDIC — Conditions of Contract for Construction 2017 as a contracts generator
- ICC — URDG 758 in the guarantee texts
- ISO — 19650, 9001, 45001, 30414, 4217
- CSI — MasterFormat
- PMI — earned value (the cost side)
- RICS / ICE — NRM2 / CESMM (the take-off sheet)
- CIOB — price build-up practice
- SHRM — BASK as a design reference
- ~500 authorities in the abbreviations glossary (ACI, ASTM, ASCE, AASHTO, ASHRAE, NFPA, NEC, IEEE, IEC, OSHA, EPA, EJCDC, AIA, ANSI, DIN, EN, BS, USGBC…) a linguistic reference only
- Security frameworks (OWASP, ISO 27001, NIST 800-53, COSO, Supabase practices) — alignment by design, not certification
- Deloitte / KPMG — mentioned as an aspiration of "presentability to auditors" in a migration header
08 Confidence statement — what can be said with confidence
The user's confidence is built on what can be proven from the code. Here is what can rightly be said with confidence about PZone ERP:
✓ Rightly said (backed by the code)
- "The accounting was designed in accordance with IFRS and the Egyptian standards (48/IFRS 15, 38/IAS 19, 10/IAS 16, IAS 12, IAS 21, IAS 2, 4/IAS 7, IFRS 9) with double-entry enforced in the database, closed periods, an immutable audit log, and segregation of duties."
- "It meets the requirements of the Egyptian Tax Authority: VAT 14%, withholding under account, and actual integration with the e-invoice system (version 1.0 document) without retaining your signing key."
- "It invokes Labor Law 14/2025, Social Insurance 148/2019 and Data Protection 151/2020 in the HR model and the access policies."
- "It generates FIDIC 2017 contracts with the clause reference, controls documents in accordance with ISO 19650, and manages quality in accordance with ISO 9001 (NCR/CAPA/approved vendor list) with gates that actually hold money."
- "It computes earned value in accordance with PMI (the cost side) and adopts a dimensional take-off on the NRM2/CESMM pattern."
- "Each company's data isolation is enforced in the database on every table automatically, with secured functions, secrets outside the code, and deployment behind confirmation gates."
Applied security and privacy measures
- Two-factor authentication (TOTP) with a self-enrollment service in "My profile" and a verification step at login.
- Transport security headers (HSTS, framing prevention, content-type sniffing prevention, referrer and permissions policies) and a Content Security Policy (CSP) baseline.
- Reading public data is limited to a restricted set of columns, and public visibility is opt-in.
- Private storage of sensitive documents with short-lived signed links generated only on opening.
- Determining the user's role by their active organization.
- A governed software supply chain: automatic dependency updates and a security scan of the code in continuous integration.
- An integrated privacy program: privacy/terms pages, consent at registration, individual account deletion (the right to erasure), and a retention/destruction policy — in enforcement of Data Protection Law 151/2020.
- Linking the FIDIC contract data to the payment-certificate engine: the retention, advance and recovery percentages are read from the contract linked to the project.