Your customers' data, your policies, your brand — protected by the controls a regulated financial institution expects, and evidenced in our Trust Center.
Certified information security management. The certificate, its registered scope and our certification body are available in the Trust Center.
Independent attestation of our security controls by a third-party auditor. The report, including its type and the criteria covered, is available under NDA through the Trust Center.
Our platform and our contracts are built to meet Saudi Arabia's Personal Data Protection Law and its Executive Regulations. The obligations are set out in our signed Data Processing Agreement.
UAE portfolios are hosted in-region. Saudi portfolios are processed in-Kingdom, as committed in our DPA. Hosting regions and sub-processors are listed in the Trust Center.
All data encrypted at rest and in transit, with managed key rotation.
Role-based access, approvals and least-privilege defaults across the platform, for your team and ours.
Every decision, message and call logged and reviewable. Your compliance team can reconstruct any account's full history. The trail is generated by the system, not assembled after the fact.
Models operate inside lender policy with logged decisions. Borrower data is used to resolve accounts, governed by the DPA, never sold.
Business continuity and disaster-recovery arrangements built for regulated finance, including back-up servicing as a product, not an afterthought.
Send them over — our security review pack is ready for procurement.