Security, built in — not bolted on
Security and privacy are part of how we design, build, and run everything — shaped by the standards this region cares about, and carried through to how we operate every day.
The frameworks that shape how we work
NCA ECC
We design around the National Cybersecurity Authority's Essential Cybersecurity Controls and KSA regulatory expectations.
PDPL
We build for the Personal Data Protection Law, with transparent, lawful handling of personal data.
ISO 27001
Our engineering follows ISO 27001 information-security practices.
OWASP & CIS
The OWASP and CIS benchmarks are our working references for application and infrastructure hardening.
Data residency
Hosting options including fully in-Kingdom, where the rules or your policy require it.
Access & audit
Role-based access, full audit trails, and tenant isolation across everything we run.
How we handle your data
- Each customer's data is kept separate by design, with tenant isolation
- Encryption in transit, and access limited by role
- In-Kingdom data residency available where required
- A full audit trail of who did what, and when
- Retention and deletion handled to agreed, lawful timelines
Built and run securely
Security at every step
Security is checked at each stage of design, build, and release, not bolted on at the end.
Change control & sign-off
Production changes go through controlled review and sign-off, with a clean audit trail.
You control where it runs
SaaS, private cloud, or on-premise, so data lives where your rules and policy require.
A straight word on compliance
The standards above describe how we engineer and operate. Where a specific engagement needs formal certification or attestation, we'll be clear about what is already in place and what we would put in place with you — no overstatement, no badges we haven't earned.
Have a security or compliance question?
Tell us what you need to satisfy, and we'll walk you through how we handle it.