Security, data residency & compliance

Siyada Tech deploys AI systems inside the customer's own environment. Data, indexes and audit logs stay where the customer's regulator expects them to be. This page states exactly what that means, and what we have not yet certified.

Last reviewed: Siyada Tech engineering

Deployment model

  • In-tenant by default: systems run in the customer's cloud subscription or data centre.
  • Private VPC and on-premises options where data cannot leave the environment.
  • No customer corpus, index or audit log is copied to Siyada-controlled infrastructure.
  • Model access is configured per deployment, including fully self-hosted models where required.

Data residency

  • Data resides wherever the tenant is deployed; for Saudi customers that is normally in-Kingdom.
  • Cross-border processing only occurs where the customer explicitly configures it.
  • Retention and deletion follow the customer's own policy, applied to indexes and logs alike.

Regulatory alignment

  • Personal Data Protection Law (PDPL): systems are designed for lawful basis, minimisation and data subject rights handling.
  • NDMO data management: classification and handling follow the customer's data governance framework.
  • NCA controls: deployments are built to sit within the customer's existing cybersecurity control environment.
  • SDAIA AI ethics principles: fairness, transparency, accountability and human oversight are implemented as product behaviour, not policy text.

Access, logging and oversight

  • Role-based access control, with retrieval filtered by the source system's permissions.
  • Immutable audit log of prompts, retrieved sources, tool calls, model version and outputs.
  • Human approval gates on defined high-impact actions.
  • Release gating through Qiyas evaluation thresholds before production rollout.

What we have not certified

  • Independent certifications (for example ISO 27001, SOC 2): [EVIDENCE REQUIRED]
  • Penetration test cadence and most recent report date: [EVIDENCE REQUIRED]
  • We state design alignment with regulation; we do not claim third-party certification we do not hold.

Frequently asked questions