ARISE
Security & Trust

Trust, built in
from the first line

ARISE is a closed, enterprise platform built for the Kingdom. PDPL-aligned, with data residency in KSA, encryption everywhere, granular access control, full audit logging, and isolated execution — so your team can move fast without trading away control.

PDPL alignedKSA data residencyEncrypted end to endPCI DSS paymentsSSO · SCIM · RBAC
How we protect you

Security on every layer

From where your data lives to how every agent runs, security is a property of the platform — not a setting you have to remember to turn on.

Data protection & PDPL compliance

Built to align with the Personal Data Protection Law (PDPL) of the Kingdom of Saudi Arabia and its Implementing Regulations. You own your data; we process it only to operate the service for you.

  • Clear, documented processor role
  • Data-subject rights supported
  • Enterprise data-processing agreements

Data residency in the Kingdom

Your data stays in the region you choose. For customers in the Kingdom, data can be kept within Saudi Arabian borders — no silent cross-border transfer.

  • In-region (KSA) hosting
  • Configurable residency boundaries
  • Full transparency on where data lives

Encryption everywhere

Your data is encrypted in transit and at rest using strong industry standards. Secrets and API keys live in isolated, encrypted vaults.

  • TLS encryption in transit
  • Strong encryption at rest
  • Isolated, encrypted secrets

Access control: SSO, SCIM & RBAC

Connect your identity provider, provision and de-provision users automatically, and give each role exactly the least access it needs — nothing more.

  • Single sign-on (SAML / OIDC)
  • SCIM user provisioning
  • Role-based access control (RBAC)

Audit logging

Every sensitive action is recorded — who signed in, what changed, and when. Export logs to your own monitoring stack to satisfy governance requirements.

  • Searchable activity trail
  • Who-did-what-when tracking
  • Export for review & compliance

Isolated cloud sandboxes

Every agent runs inside its own isolated, ephemeral cloud sandbox. Runs share no state, so the blast radius of any single task is contained by design.

  • Strict isolation between runs
  • Ephemeral, wiped after use
  • Scoped permissions per task

Secure payments

Payments are processed through Moyasar, the Saudi gateway that is PCI DSS compliant and PDPL-ready. Your card details never touch or stay on our servers.

  • Saudi Moyasar gateway
  • PCI DSS compliant
  • No card data stored by us

Deployment options

Run it fully managed on our cloud, inside your own private VPC, or entirely on your infrastructure — the same platform, you decide where it lives.

  • Fully managed cloud
  • Dedicated private VPC
  • Enterprise self-host
Data residency

Your data stays in the Kingdom

For customers in Saudi Arabia, your data can be stored and processed within the Kingdom. You always know which region holds your data, and it never crosses borders without your say.

  • In-region (KSA) hosting for local customers
  • Configurable residency boundaries per customer
  • No cross-border transfer without your consent

Region

Saudi Arabia (KSA)

Active
Data storageIn-region
ProcessingIn-region
BackupsIn-region
Cross-border transferOnly with consent
Deployment

You decide where it runs

The same platform, three ways to run it. Start fully managed, move into your own private cloud, or self-host on your infrastructure — without giving up any capability.

Managed cloud

Hosted, operated and updated by us, with data residency in your region. The fastest way to go live.

Private VPC

A dedicated deployment inside your own cloud environment, isolated from others with private networking.

Enterprise self-host

Run the entire platform on your own infrastructure — even fully air-gapped. You own everything.

Responsible disclosure

Found a vulnerability? We want to hear from you. Report it privately and our security team will acknowledge it quickly and work with you toward a fix. Please give us a reasonable window to remediate before any public disclosure.

We acknowledge reports within two business days.

Talk to us

Need a deeper security review?

Our team will walk your security and compliance leads through our controls, data handling, residency, and deployment options — and answer your questionnaire.

PDPL · KSA residency · encryption · SSO · audit logs · isolated execution

Security & Trust | ARISE