All rights are reserved ® 2026
IJD FOR ELECTRONIC SERVICES AND SOFTWARES
آي چاي دي للخدمات الالكترونية والبرمجيات
Tax Reg. 602-315-883 C.R. 10620-00000-21965
Tax Reg. 602-315-883 C.R. 10620-00000-21965
IJD Creatives provides authorized penetration testing and offensive security assessment services to help organizations identify exploitable weaknesses across web applications, mobile applications, APIs, backend systems, cloud environments, and supporting infrastructure.
All offensive security activities are conducted only within a formally approved scope and with explicit written authorization from the system owner before testing begins.
Our objective is to identify security weaknesses safely, validate their potential impact, and provide actionable remediation guidance to engineering and security teams.
The Application Security & Penetration Testing Function at IJD Creatives is responsible for planning and conducting authorized offensive security assessments.
The function works independently within an approved Rules of Engagement and coordinates with application owners, engineering teams, infrastructure teams, and designated security contacts.
The function is responsible for:
Islam Diab
CEO & Security Lead
IJD Creatives
The Security Lead oversees the authorization, scope definition, execution governance, and reporting requirements for offensive security assessments performed by IJD Creatives.
Security testing is performed only after the required authorization and engagement scope have been approved.
Security Contact:
security@ijdcreatives.com
Every penetration-testing engagement requires explicit written authorization from the system owner before any testing begins.
The Rules of Engagement define:
Testing is strictly limited to the systems, assets, techniques, and time period defined in the approved scope.
IJD Creatives does not conduct unauthorized penetration testing or offensive security testing against third-party systems.
Before testing starts, the following process is completed:
The system owner or authorized client representative provides written authorization for the security assessment.
The assessment scope identifies the exact systems, applications, APIs, infrastructure, environments, and testing boundaries.
Permitted testing activities, restrictions, testing dates, escalation contacts, and reporting expectations are documented.
The Security Lead reviews the engagement scope and authorization before offensive testing begins.
Testing is performed strictly within the approved scope.
Confirmed findings are documented and communicated to the system owner or authorized security contact.
Where requested, IJD Creatives supports remediation and performs retesting to verify that identified vulnerabilities have been resolved.
Our web application assessments may review security controls related to:
API assessments may include:
Mobile application assessments may cover:
Mobile applications are assessed together with relevant backend services where appropriate.
Infrastructure assessments may include authorized review of:
Potential vulnerabilities are reviewed to determine whether they represent genuine and actionable security risks.
Validation focuses on confirming:
Testing is designed to minimize unnecessary disruption to production systems.
Security assessment reports may include:
Sensitive security reports are provided only to authorized recipients.
IJD Creatives follows a controlled and authorization-based approach to offensive security.
We do not perform:
Testing activities are conducted for legitimate security assessment, risk reduction, remediation, and validation purposes.
Depending on the engagement, our assessments may reference industry-recognized security guidance including:
Use of these frameworks does not imply external certification unless explicitly stated.
For authorized penetration testing and offensive security inquiries:
IJD Creatives
Application Security & Penetration Testing Function
Security Lead: Islam Diab
Email: security@ijdcreatives.com
Security is a core part of how IJD Creatives designs, develops, deploys, and maintains software.
Our security program focuses on protecting the applications, infrastructure, APIs, data, and development environments that we own or maintain.
Our security activities include application-security review, vulnerability management, secure code review, infrastructure-security review, remediation validation, access-control review, security monitoring, and incident-response support.
Islam Diab — CEO & Security Lead
Islam Diab is responsible for overseeing application security, infrastructure security, vulnerability management, secure software-development practices, and authorized security-assessment activities at IJD Creatives.
Our security function works closely with engineering and infrastructure teams throughout the development lifecycle.
Areas of responsibility include:
Authorized Testing
IJD Creatives conducts defensive security assessments, vulnerability identification and validation only against systems owned or maintained by the company, or client systems for which explicit authorization has been granted by the system owner.
We do not perform unauthorized security testing.
Security-related inquiries can be directed to:
Islam Diab
CEO & Security Lead
IJD Creatives