No factory is listed until Sam has stood in it.
Alibaba lets any factory self-list. Zafir360 doesn't. Every supplier is personally visited and verified before a single product goes live — there is no automated path to a listing. Trust is a gate, not a badge you can buy.
Verified Suppliers
Every factory passes Sam's review before it's admitted — nobody self-lists.
Secure Payments
PCI DSS Level 1, tokenised, never stored — the same standard banks are held to.
Buyer Protection
Escrow holds the money until delivery actually happens — not on order confirmation.
Fraud Detection
IP scoring and device fingerprinting run quietly in the background — a 3-strike policy does the rest.
The badge that can't be bought.
Factory visit, not a form
Gold badge shows the exact visit date. It's issued after a personal factory inspection — not after a document upload.
Gated onboarding
Suppliers submit company details, photos, capacity, and certifications. Nothing goes live without Sam's approval.
Instant blacklist
Sam can delist a supplier immediately. Active RFQs are reassigned and buyers with open orders are protected automatically.
Escrow, KYB, and identity checks at every tier.
Trade license, commercial registration, and owner national ID required before a business buyer can see wholesale prices.
Buyer funds sit in Zafir360 escrow and release to the supplier at agreed delivery milestones — not on order confirmation.
Buyers file disputes for wrong goods, below-spec quality, short quantity, or late delivery — with evidence attached.
SMS OTP required on any new-device login to a consumer account.
PII encrypted at rest (AES-256); payment data is never stored, only tokenised; KYC documents sit in access-restricted storage.
KYC on wallet balances above IQD 1M, suspicious-transaction reporting above IQD 50M, AML screening on large B2B payments.
| Control | What it does |
|---|---|
| KYB Verification | Trade license, commercial registration, and owner national ID required before a business buyer can see wholesale prices. |
| Escrow Payment | Buyer funds sit in Zafir360 escrow and release to the supplier at agreed delivery milestones — not on order confirmation. |
| Wholesale Dispute Resolution | Buyers file disputes for wrong goods, below-spec quality, short quantity, or late delivery — with evidence attached. |
| Consumer 2FA | SMS OTP required on any new-device login to a consumer account. |
| Data Protection | PII encrypted at rest (AES-256); payment data is never stored, only tokenised; KYC documents sit in access-restricted storage. |
| Iraqi Payment Compliance | KYC on wallet balances above IQD 1M, suspicious-transaction reporting above IQD 50M, AML screening on large B2B payments. |
What runs underneath the trust badges.
Encryption
TLS 1.3 everywhere. AES-256 for PII at rest. Payment data tokenised, never stored.
OWASP Top 10
Parameterised queries, XSS sanitisation, CORS whitelist, AWS WAF, CSP headers.
Continuous scanning
Snyk dependency and container scans, SAST in CI, weekly OWASP ZAP against staging.
Fraud detection
IP scoring, device fingerprinting, and rule-based detection with a three-strike ban policy.
What isn't allowed on Zafir360.
A prohibited-items policy written for the Iraqi context — enforced at listing time by the moderation queue, not after the fact.
Weapons
No listing category permits weapons or replicas.
Alcohol & drugs
Excluded outright under the Iraqi regulatory context.
Counterfeit goods
Blocked at moderation; repeat attempts escalate to a supplier or seller ban.
Adult & political content
Excluded from every tier of the catalogue.