Security & compliance
Security, data residency & compliance
We deploy AI inside the client's own environment. Data, indexes and audit logs stay where the client's regulator expects them. This page states exactly what that means, and what we have not certified.
01Deployment model
- In-tenant by default: systems run in the client's cloud subscription or data centre.
- Private network and on-premises options where data cannot leave the environment.
- No client corpus, index or audit log is copied to Siyada-controlled infrastructure.
- Model access is configured per deployment, including fully self-hosted models where required.
02Data residency
- Data resides wherever the tenant is deployed; for Saudi clients that is normally in the Kingdom.
- Cross-border processing happens only where the client explicitly configures it.
- Retention and deletion follow the client's own policy, applied to indexes and logs alike.
03Regulatory alignment
- Personal Data Protection Law (PDPL): systems are designed for lawful basis, data minimisation and data-subject rights.
- NDMO data management: classification and handling follow the client's data-governance framework.
- NCA controls: deployments are built to sit within the client's existing cybersecurity controls.
- SDAIA AI-ethics principles: fairness, transparency, accountability and human oversight are built in as product behaviour, not policy text.
04Access, logging and oversight
- Role-based access, with retrieval filtered by the source system's permissions.
- Immutable audit log of prompts, retrieved sources, tool calls, model version and outputs.
- Human approval on defined high-impact actions.
- Release gating on agreed evaluation thresholds before production rollout.
05What we have not certified
- Independent certifications (for example ISO 27001, SOC 2): [EVIDENCE REQUIRED]
- Penetration-test cadence and most recent report date: [EVIDENCE REQUIRED]
- We state design alignment with regulation. We do not claim third-party certification we do not hold.
?Asked often
Questions
Where does our data go?
Nowhere. Systems are deployed inside your tenant, so the corpus, indexes and audit logs stay in your environment under your residency rules.
Is Siyada Tech PDPL compliant?
Our systems are designed against PDPL requirements, and deployment keeps personal data in your environment. Compliance is assessed for each deployment with your data protection officer.
Do you hold ISO 27001 or SOC 2?
Certification status is listed on this page and is currently marked as evidence required. We do not claim certifications we do not hold.
Can we run fully self-hosted models?
Yes. Where you cannot use a hosted model, deployments can run self-hosted models inside the same environment.
How do you handle AI oversight?
Scoped permissions, human approval on high-impact actions, evaluation gates before release, and a full audit log of every action.
Last reviewed · Siyada Tech engineering
Start with one workflow
Bring your security reviewer to the first conversation. The answers above are the ones we will give in writing.