Trust & compliance
Trust is a deliverable, not a slogan.
We build regulated software for a living, so we hold ourselves to the same bar we hold our clients' systems to. This page states our posture plainly — including the parts that are still on the roadmap.
Regimes we build against
| Regime | Instrument | Applies to |
|---|---|---|
| UAE PDPL | Federal Decree-Law 45/2021 | Personal data processed in the UAE |
| DIFC Data Protection Law | DIFC Law No. 5 of 2020 | DIFC-registered controllers |
| ADGM Data Protection Regulations | ADGM DPR 2021 | ADGM-registered controllers |
| Dubai Data Law | Law No. 26 of 2015 | Dubai government & semi-government data |
| India DPDP Act | Act 46 of 2023 | Personal data processed in India |
| EU GDPR | Regulation 2016/679 | EU data subjects & extraterritorial scope |
Your data
How we handle what you entrust us with.
We act as processor, you remain controller
Your data is yours. We process only on your documented instructions and return or delete it on termination.
Data residency is honoured, not approximated
Hosting region is a contract term. UAE work stays in-region unless you instruct otherwise in writing.
Your data never trains a model
Client content is excluded from model training and from any shared cache. Zero-retention endpoints where a hosted model is required.
Defined retention, certified deletion
Every data class has a retention period and a deletion path. Deletion is verified, not assumed.
Security baseline
The floor, not the ceiling.
These apply to every project from day one — they are not premium add-ons and they are not negotiable downward.
- Zero-trust access with MFA; no password auth, no shared accounts
- Encryption in transit and at rest across every environment
- Least-privilege, named identities; production is break-glass only
- Branch protection, mandatory peer review, CI-gated deploys
- Full audit logging on every privileged and data-touching action
- Secrets in a managed vault — never in source control or images
Governed AI
AI with a paper trail.
in production today·committed on the roadmap
Every AI call is tenant-anchored and audited
Prompt hashes and outcomes are logged; raw prompts of sensitive tenants never leave the tenant boundary.
AI cannot act alone
A single governed write path requires human approval, and the approver can never be the requester.
Egress masking of personal data
PII is masked or tokenised before it reaches any model boundary.
Evaluation gate on generated output
Outputs hard-fail on hallucinated citations or unsupported claims before they reach a user.
Per-tenant kill switch
Any tenant can disable AI features instantly, without a deploy.
Confidential-computing (TEE) endpoints
For the most sensitive paths, data stays encrypted even while the model processes it.
What we evidence — and what we refuse to claim
What we provide
- Control documentation and a compliance pack per engagement
- Audit logs exportable to your team on request
- Penetration-test findings with remediation records
- A named security contact and a defined disclosure path
What we don't claim
- Certification badges we have not actually earned
- “Military-grade” or “unbreakable” language of any kind
- Client names or logos without written approval
- AI capability we cannot demonstrate on your data
Put our posture in front of your security team.
Request the compliance pack and security questionnaire — we answer them in writing, not on a sales call.