1. Controls in place
The following controls are enabled in the service environment, and this statement is updated on any material change:
- Access control and authentication
- Role-based permissions
- Tenant isolation at the database layer
- Encryption in transit
- Encryption at rest
- Audit logging of sensitive events
- Secret and key management
- Data export restrictions
2. Access and permissions
- Access is based on roles, departments and permissions configured by the organisation admin.
- Workspace isolation is enforced at the database layer.
- Sensitive permission changes are recorded in audit logs.
3. Hosting and processing
Data may be processed or hosted inside or outside the Kingdom of Saudi Arabia depending on customer configuration, the nature of the service and approved service providers, in line with applicable regulations and contractual obligations. Appropriate contractual and technical safeguards apply to any processing or transfer of data outside the Kingdom.
No statement about in-Kingdom data residency is made before the hosting configuration is confirmed.
4. Incident management
On a suspected security incident, containment, investigation and remediation steps are taken, and statutory notifications are made where the applicable conditions are met.
5. Vulnerability reporting
Report vulnerabilities to info@data.sa without exploiting or publishing them. Security testing without prior written authorisation is prohibited.
Version history
- 1.014 August 2025Approved for publication.
