Trust & compliance
Sovereignty you can put in a contract and check in a log.
سيادة يمكن توثيقها في العقد والتحقق منها في السجلات
In writing
Six commitments in every contract
No training on your data
Your prompts, documents and outputs are never used to train a model for anyone else.
No offshore inference by default
Every model runs in the Kingdom. Any external model is off unless you enable it, per workspace, in writing.
Zero-retention option
Prompts and outputs can be kept only as long as the request takes, with metadata-only logging.
Your keys, your exit
Revoke your key to make stored data unreadable; export everything in open formats when you leave.
Named access
Privileged access by named, vetted staff in Saudi Arabia, time-limited and recorded.
Honest about status
We say which certifications and registrations we hold and which are in progress. We never imply one we do not have.
Regulatory mapping
How the platform is designed to support each framework
| Framework | What it covers | How SoverAIn supports it |
|---|---|---|
| PDPL (SDAIA) | Personal data protection, including transfers outside the Kingdom | Processing and storage in-Kingdom; PII redaction before inference; records of processing; DPA per customer |
| NCA ECC | Essential cybersecurity controls | Asset inventory, MFA, privileged access management, logging and monitoring, vulnerability management, backup |
| NCA CCC | Cloud cybersecurity controls | Tenant isolation, customer-managed keys, in-Kingdom hosting, cloud provider and customer responsibilities set out per deployment |
| CST Cloud Computing Regulatory Framework | Cloud services offered in Saudi Arabia | Designed to operate within the framework; registration status confirmed with each customer |
| NDMO data classification | Public, Restricted, Secret, Top Secret | A deployment model mapped to each classification level |
| SDAIA AI Ethics Principles and generative AI guidance | Fairness, privacy, reliability, transparency, accountability | Evaluation sets, citations, audit trail, a named human approver for consequential actions |
| Sector rules (for example SAMA, healthcare regulators) | Outsourcing, cloud and data rules for regulated sectors | Dedicated or private deployment, with the evidence pack your regulator asks for |
Security
Controls in every deployment
| Area | Control |
|---|---|
| Encryption | TLS 1.2+ in transit; AES-256 at rest; customer-managed keys in an HSM |
| Isolation | Per-tenant networks, storage and keys; dedicated hardware on Dedicated and Private |
| Identity | SSO with your identity provider; MFA; role-based access to models, data sources and workspaces |
| Audit | Append-only log of every call: user, model version, policy, sources, latency; export to your SIEM |
| Guardrails | PII detection and redaction, content policies, prompt-injection defences on retrieved content |
| Resilience | Backups and recovery within the Kingdom; capacity reservations on Dedicated |
Certification status
We will tell you exactly where we stand.
- We do not claim any certification, accreditation or regulatory registration on this site.
- For each customer we state, in the contract, the current status of every certification and registration relevant to their deployment.
- We share our control mapping and answer your security questionnaire directly, before any data moves.
Bring your security questionnaire.
We will walk your security, risk and legal teams through residency, keys, access and the audit trail before a pilot starts.
