Overview
Our platforms are designed to SDAIA guidance, NCA ECC controls and the PDPL.
This holds for every platform in the catalog, not one product alone.
Sectors where data sovereignty and regulatory compliance are not optional - government, finance, legal, healthcare - are treated as a starting constraint, not something bolted on after a security review flags a gap.
What this page claims, and what it does not
Alignment describes how the platform is designed and deployed. It is not a third-party certification, and this page does not claim one. Where a certification is held, it belongs here with its issuing body, its scope and its date.
Access control and audit records
Access control is explicit: assign tasks, define who can touch which system, and set permissions clearly enough that handoffs don't turn into confusion or mistakes. Full audit logging and continuous monitoring are standard on Workforces and Seamless Enterprise deployments, not an add-on tier.
Audit records stay inside the deployment boundary. On an on-premises or air-gapped deployment the log never leaves your environment, for the same reason the data doesn't.
Retention periods, log schema and export formats are not published here. They're deployment-specific - confirm them for your deployment during procurement rather than inferring them from this page.
Sub-processors
A sub-processor register lists the third parties that may process customer data on a vendor's behalf.
No sub-processor register is published on this site yet, and this page is not a substitute for one. Until one is published here, treat the sub-processor list as an open item to raise in procurement rather than a question this page has answered.
On a fully on-premises or air-gapped deployment, the models and the platform run inside your own environment.
Where the rest of the answer lives
- Security - data masking on sensitive fields, audit logging and continuous monitoring.
- Deployment options - cloud API, on-premises, and sovereign or air-gapped.
- Data residency - in-Kingdom hosting, and what stays inside your walls.
Also in the Trust Center
- SecurityEvery deployment is designed from day one to SDAIA guidance and NCA ECC controls.
- ComplianceOur platforms are designed to SDAIA guidance, NCA ECC controls and the PDPL.
- Deployment OptionsOn the cloud, on your servers, or fully air-gapped.
- Data ResidencyOn dedicated or on-premises deployments, your data stays in the Kingdom.
Talk to us about Compliance
Every good solution starts with a clear question. Ask us, and our team is with you from question to solution.
