Security

Built for the controls your risk team already runs.

Your customers' data, your policies, your brand — protected by the controls a regulated financial institution expects, and evidenced in our Trust Center.

Certifications

Certified, attested, auditable.

ISO 27001:2022

Certified information security management. The certificate, its registered scope and our certification body are available in the Trust Center.

SOC 2

Independent attestation of our security controls by a third-party auditor. The report, including its type and the criteria covered, is available under NDA through the Trust Center.

Saudi PDPL

Our platform and our contracts are built to meet Saudi Arabia's Personal Data Protection Law and its Executive Regulations. The obligations are set out in our signed Data Processing Agreement.

Data residency

UAE portfolios are hosted in-region. Saudi portfolios are processed in-Kingdom, as committed in our DPA. Hosting regions and sub-processors are listed in the Trust Center.

Controls

Defense in depth, evidence by default.

Encryption

All data encrypted at rest and in transit, with managed key rotation.

Access control

Role-based access, approvals and least-privilege defaults across the platform, for your team and ours.

Complete audit trails

Every decision, message and call logged and reviewable. Your compliance team can reconstruct any account's full history. The trail is generated by the system, not assembled after the fact.

AI data governance

Models operate inside lender policy with logged decisions. Borrower data is used to resolve accounts, governed by the DPA, never sold.

Resilience

Business continuity and disaster-recovery arrangements built for regulated finance, including back-up servicing as a product, not an afterthought.

Send this page to your CISO.

Send them over — our security review pack is ready for procurement.

Book a consultation