Security & Compliance

This page sets out what we actually commit to in data protection and regulatory compliance, and where customer data is hosted.

Controls we build to

  • NCA ECC Essential Cybersecurity Controls — National Cybersecurity Authority
  • PDPL Saudi Personal Data Protection Law
  • ISO/IEC 27001 Information security management framework
  • SAMA CSF Saudi Central Bank cybersecurity framework (for regulated customers)

Who gets in, what they see, and where it stays

Encryption

Data encrypted in transit (TLS 1.2+) and at rest.

Access control

Role-based permissions, one identity via OpenID Connect, and an audit trail on every action.

Tenant isolation

Per-organisation separation at both the application and database layer.

Backup & recovery

Scheduled backups with tested restores.

Data residency

Customer data is hosted inside the Kingdom of Saudi Arabia.

Platform data is stored and processed inside the Kingdom, and each organisation's data is separated at both the application and the database layer. Backups stay within the same boundary.

Where AI processing happens

The AI features in Musahm Vault — ask your documents, the assistant, and field extraction — run on Google's Gemini models, a service that operates outside the Kingdom.

  • The feature is off unless it is switched on, and can be disabled per organisation.
  • When it is on, the text to be analysed is sent to that service to be processed, and nothing else is.
  • Storage stays inside the Kingdom; what leaves is the text sent for processing, at the moment the question is asked.
  • Where that is not acceptable — government bodies, or customers regulated by the central bank — the platform runs with the feature off and every other module unchanged.

To request compliance documentation or a penetration test report, contact us. Contact Us