Encryption
Data encrypted in transit (TLS 1.2+) and at rest.
This page sets out what we actually commit to in data protection and regulatory compliance, and where customer data is hosted.
Data encrypted in transit (TLS 1.2+) and at rest.
Role-based permissions, one identity via OpenID Connect, and an audit trail on every action.
Per-organisation separation at both the application and database layer.
Scheduled backups with tested restores.
Customer data is hosted inside the Kingdom of Saudi Arabia.
Platform data is stored and processed inside the Kingdom, and each organisation's data is separated at both the application and the database layer. Backups stay within the same boundary.
The AI features in Musahm Vault — ask your documents, the assistant, and field extraction — run on Google's Gemini models, a service that operates outside the Kingdom.
To request compliance documentation or a penetration test report, contact us. Contact Us