Trust & compliance

Trust is a deliverable, not a slogan.

We build regulated software for a living, so we hold ourselves to the same bar we hold our clients' systems to. This page states our posture plainly — including the parts that are still on the roadmap.

Regimes we build against

RegimeApplies to
UAE PDPLPersonal data processed in the UAE
DIFC Data Protection LawDIFC-registered controllers
ADGM Data Protection RegulationsADGM-registered controllers
Dubai Data LawDubai government & semi-government data
India DPDP ActPersonal data processed in India
EU GDPREU data subjects & extraterritorial scope

Your data

How we handle what you entrust us with.

We act as processor, you remain controller

Your data is yours. We process only on your documented instructions and return or delete it on termination.

Data residency is honoured, not approximated

Hosting region is a contract term. UAE work stays in-region unless you instruct otherwise in writing.

Your data never trains a model

Client content is excluded from model training and from any shared cache. Zero-retention endpoints where a hosted model is required.

Defined retention, certified deletion

Every data class has a retention period and a deletion path. Deletion is verified, not assumed.

Security baseline

The floor, not the ceiling.

These apply to every project from day one — they are not premium add-ons and they are not negotiable downward.

  • Zero-trust access with MFA; no password auth, no shared accounts
  • Encryption in transit and at rest across every environment
  • Least-privilege, named identities; production is break-glass only
  • Branch protection, mandatory peer review, CI-gated deploys
  • Full audit logging on every privileged and data-touching action
  • Secrets in a managed vault — never in source control or images

Governed AI

AI with a paper trail.

in production today·committed on the roadmap

Every AI call is tenant-anchored and audited

Prompt hashes and outcomes are logged; raw prompts of sensitive tenants never leave the tenant boundary.

AI cannot act alone

A single governed write path requires human approval, and the approver can never be the requester.

Egress masking of personal data

PII is masked or tokenised before it reaches any model boundary.

Evaluation gate on generated output

Outputs hard-fail on hallucinated citations or unsupported claims before they reach a user.

Per-tenant kill switch

Any tenant can disable AI features instantly, without a deploy.

Confidential-computing (TEE) endpoints

For the most sensitive paths, data stays encrypted even while the model processes it.

What we evidence — and what we refuse to claim

What we provide

  • Control documentation and a compliance pack per engagement
  • Audit logs exportable to your team on request
  • Penetration-test findings with remediation records
  • A named security contact and a defined disclosure path

What we don't claim

  • Certification badges we have not actually earned
  • “Military-grade” or “unbreakable” language of any kind
  • Client names or logos without written approval
  • AI capability we cannot demonstrate on your data

Put our posture in front of your security team.

Request the compliance pack and security questionnaire — we answer them in writing, not on a sales call.