Security & Compliance

This page sets out what we actually commit to in data protection and regulatory compliance, and where customer data is hosted.

Controls we build to

  • NCA ECC Essential Cybersecurity Controls — National Cybersecurity Authority
  • PDPL Saudi Personal Data Protection Law
  • ISO/IEC 27001 Information security management framework
  • SAMA CSF Saudi Central Bank cybersecurity framework (for regulated customers)

World-class Enterprise Security

Encryption

Data encrypted in transit (TLS 1.2+) and at rest.

Access control

Role-based permissions, one identity via OpenID Connect, and an audit trail on every action.

Tenant isolation

Per-organisation separation at both the application and database layer.

Backup & recovery

Scheduled backups with tested restores.

Data residency

Customer data is hosted inside the Kingdom of Saudi Arabia.

To request compliance documentation or a penetration test report, contact us. Contact Us