Trust is earned in writing.
Our security posture, stated plainly: what is certified, what is in progress, and how the platform and hardware are engineered either way.
Programs and alignments, stated honestly.
Language below is deliberate: a program is not a certificate, and we will not blur the line.
SOC 2 program
A SOC 2 Type II program is underway with an independent auditor. Report available to customers under NDA once issued.
ISO 27001-aligned
The information security management system follows ISO 27001 control structure. Certification is on the compliance roadmap.
HIPAA-capable
Architecture supports HIPAA-regulated deployments, including BAAs on Enterprise agreements, for healthcare customers in applicable regions.
PDPL-ready
Data handling is designed for Saudi PDPL requirements, including in-Kingdom residency, data-subject rights tooling, and processing records.
Platform controls
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- SSO via SAML/OIDC, provisioning via SCIM — Entra ID and Okta first-class
- Role-based access control down to site, module, field, and action
- Complete, immutable audit logs for every read-sensitive and write action
- Tenant isolation with per-tenant encryption keys on private cloud
- Data residency options: in-Kingdom (KSA), in-region (UAE), EU, US
- Backups with tested restore procedures and defined RPO/RTO per tier
- Agent governance: permissioned scopes, approval thresholds, reversible actions
Hardware security
- Signed firmware with staged rollout and automatic rollback
- TLS from the sensor: mutual authentication from device to platform
- No inbound ports on OpsSense Edge — outbound-only connections
- Per-device credentials; compromised devices are revoked individually
- Local buffering keeps data integrity through network loss
See your operations run themselves.
A 30-minute walkthrough with an operations engineer. Your assets, your workflows, your questions.