HomeSecurity and trust

Trust is proven, not claimed

Full isolation for every organization, published controls on platform operator access that you can see for yourself, quality gates that can’t be bypassed, rehearsed recovery with a measured time, and alignment with international security and privacy standards.

Layers of protection

Controls designed into the architecture, not bolted on later

A database per organizationOne isolation model for every customer, unchanged by plan, with automated isolation tests on every merge
Identity and single sign-onMulti-factor authentication for sensitive accounts, with the person kept separate from the account and from the position assignment
Encryption and separate keysEncryption in transit and at rest, a dedicated key per tenant, and centralized secrets management
Controlled operator accessTime-boxed, scoped sessions with a justification and ticket, writes only with a second approval, and a transparency log for you
Protection against bulk extractionRead thresholds and alerts on unusual patterns, and full exports of your database only with your approval
Mandatory quality gatesSAST plus DAST, dependency, secrets, container and accessibility checks that no role can bypass manually
Tested recoveryA single customer’s database restored to an isolated environment and checked for completeness, consistency and isolation
Governed AIA model gateway with a per-organization policy, no training on your content, and a separate audit log
Employee privacyA portal that shows employees what’s stored about them and who has viewed it, with requests to correct or object
Recovery and availability

Published targets for every plan, tested at least twice a year

Standard

RPO
hours
RTO
8 Hours
Availability
99.5%

Enterprise

RPO
15 minutes
RTO
4 Hours
Availability
99.9%

Enterprise+

RPO
5 minutes
RTO
Two hours
Availability
99.95%

A monthly SLA compliance report, maintenance windows announced in advance, a status page for tenants, and a published post-incident review for every high-severity incident.

Standards alignment

Built to standards your auditor already knows

Alignment, not a certification claim: the evidence is available in each tenant’s trust center.

ISO/IEC 27001

Information security management, 2022 edition and Amendment 2024

ISO/IEC 27701

Privacy information management

OWASP ASVS 5.0

Application security requirements, with a fixed reference and version

WCAG 2.2 AA

Accessibility design target, in Arabic and English

Explicit contractual disclosure

A clause in the SLA and the data processing agreement describing when and how the operator may access your data, and your rights to review, object and receive periodic reports.

Independent penetration testing

Carried out regularly by an independent party, with documented remediation and retesting, and a summary available to customers.

Privacy

Your data is yours, and how it is processed is disclosed

The platform processes the entity’s data as a data processor under the Personal Data Protection Law and its regulations. Processing details are set out in the license agreement and the data processing agreement.

Within the Kingdom

Data and its backups are stored in data centers inside the Kingdom, and each entity has its own separate database.

No training on your data

Entity data is never used to train any AI model, and AI capabilities run on activation switches approved by the entity.

Documented operator access

Provider staff can view data only through an access session approved by a second party, which is visible to the entity in the Trust center.

Data subject rights

Employees can view their data, request corrections or object to its processing from the “My data privacy” page in the platform.

Request the security controls document

A document you can hand to your security team before signing, covering operator access controls and the recovery plan.