Trust is proven, not claimed
Full isolation for every organization, published controls on platform operator access that you can see for yourself, quality gates that can’t be bypassed, rehearsed recovery with a measured time, and alignment with international security and privacy standards.
Controls designed into the architecture, not bolted on later
Published targets for every plan, tested at least twice a year
Standard
- RPO
- hours
- RTO
- 8 Hours
- Availability
- 99.5%
Enterprise
- RPO
- 15 minutes
- RTO
- 4 Hours
- Availability
- 99.9%
Enterprise+
- RPO
- 5 minutes
- RTO
- Two hours
- Availability
- 99.95%
A monthly SLA compliance report, maintenance windows announced in advance, a status page for tenants, and a published post-incident review for every high-severity incident.
Built to standards your auditor already knows
Alignment, not a certification claim: the evidence is available in each tenant’s trust center.
ISO/IEC 27001
Information security management, 2022 edition and Amendment 2024
ISO/IEC 27701
Privacy information management
OWASP ASVS 5.0
Application security requirements, with a fixed reference and version
WCAG 2.2 AA
Accessibility design target, in Arabic and English
Explicit contractual disclosure
A clause in the SLA and the data processing agreement describing when and how the operator may access your data, and your rights to review, object and receive periodic reports.
Independent penetration testing
Carried out regularly by an independent party, with documented remediation and retesting, and a summary available to customers.
Your data is yours, and how it is processed is disclosed
The platform processes the entity’s data as a data processor under the Personal Data Protection Law and its regulations. Processing details are set out in the license agreement and the data processing agreement.
Within the Kingdom
Data and its backups are stored in data centers inside the Kingdom, and each entity has its own separate database.
No training on your data
Entity data is never used to train any AI model, and AI capabilities run on activation switches approved by the entity.
Documented operator access
Provider staff can view data only through an access session approved by a second party, which is visible to the entity in the Trust center.
Data subject rights
Employees can view their data, request corrections or object to its processing from the “My data privacy” page in the platform.
Request the security controls document
A document you can hand to your security team before signing, covering operator access controls and the recovery plan.