Trust & compliance

Sovereignty you can put in a contract and check in a log.

What we commit to in writing, how the platform maps to Saudi regulation, and an honest account of what is certified and what is not yet.

سيادة يمكن توثيقها في العقد والتحقق منها في السجلات

In writing

Six commitments in every contract

No training on your data

Your prompts, documents and outputs are never used to train a model for anyone else.

No offshore inference by default

Every model runs in the Kingdom. Any external model is off unless you enable it, per workspace, in writing.

Zero-retention option

Prompts and outputs can be kept only as long as the request takes, with metadata-only logging.

Your keys, your exit

Revoke your key to make stored data unreadable; export everything in open formats when you leave.

Named access

Privileged access by named, vetted staff in Saudi Arabia, time-limited and recorded.

Honest about status

We say which certifications and registrations we hold and which are in progress. We never imply one we do not have.

Regulatory mapping

How the platform is designed to support each framework

This describes design, not a compliance opinion. Your obligations depend on your sector and your data, and are confirmed with your advisers.
FrameworkWhat it coversHow SoverAIn supports it
PDPL (SDAIA)Personal data protection, including transfers outside the KingdomProcessing and storage in-Kingdom; PII redaction before inference; records of processing; DPA per customer
NCA ECCEssential cybersecurity controlsAsset inventory, MFA, privileged access management, logging and monitoring, vulnerability management, backup
NCA CCCCloud cybersecurity controlsTenant isolation, customer-managed keys, in-Kingdom hosting, cloud provider and customer responsibilities set out per deployment
CST Cloud Computing Regulatory FrameworkCloud services offered in Saudi ArabiaDesigned to operate within the framework; registration status confirmed with each customer
NDMO data classificationPublic, Restricted, Secret, Top SecretA deployment model mapped to each classification level
SDAIA AI Ethics Principles and generative AI guidanceFairness, privacy, reliability, transparency, accountabilityEvaluation sets, citations, audit trail, a named human approver for consequential actions
Sector rules (for example SAMA, healthcare regulators)Outsourcing, cloud and data rules for regulated sectorsDedicated or private deployment, with the evidence pack your regulator asks for

Security

Controls in every deployment

AreaControl
EncryptionTLS 1.2+ in transit; AES-256 at rest; customer-managed keys in an HSM
IsolationPer-tenant networks, storage and keys; dedicated hardware on Dedicated and Private
IdentitySSO with your identity provider; MFA; role-based access to models, data sources and workspaces
AuditAppend-only log of every call: user, model version, policy, sources, latency; export to your SIEM
GuardrailsPII detection and redaction, content policies, prompt-injection defences on retrieved content
ResilienceBackups and recovery within the Kingdom; capacity reservations on Dedicated

Certification status

We will tell you exactly where we stand.

SoverAIn is onboarding design partners. Certifications and registrations are pursued as the platform moves to general availability.
  • We do not claim any certification, accreditation or regulatory registration on this site.
  • For each customer we state, in the contract, the current status of every certification and registration relevant to their deployment.
  • We share our control mapping and answer your security questionnaire directly, before any data moves.

Bring your security questionnaire.

We will walk your security, risk and legal teams through residency, keys, access and the audit trail before a pilot starts.