Security & Trust
Security
you can inspect.
What Glovia can do today, what is designed for regulation, what is on the roadmap, and which certifications we will publish only when issued.
Enterprise buyers should not have to guess which claims are live, which are design intent, and which are third-party attestations. This page keeps those categories separate.
Currently available
Capabilities in the platform architecture and typical deployments.
- Private cloud or on-premise hosting
- Saudi-region deployment options configurable by agreement (provider, residency, and access documented in the deployment schedule)
- End-to-end encryption
- Role-based access control
- Audit logging
- Tenant isolation. No cross-customer data sharing
- Dedicated AI compute per client
- Disaster recovery and failover patterns
- AI decision audit trail
Compliance-aligned design
Controls and patterns designed to support these frameworks. Not a certification claim.
- Zero Trust architecture
- SOC 2-aligned control design
- ISO 27001-aligned control design
- NCA, SAMA, and NDMO alignment (alignment ≠ certificate)
Planned
Intended attestations and publications. Not yet complete.
- Independent SOC 2 Type II report
- ISO 27001 certification
- Public summary of third-party audit results
Certifications obtained
Only independent attestations already issued appear here.
None published yet. We will list SOC 2, ISO 27001, or equivalent reports here only after they are officially obtained.
Controls
How trust is designed in.
Hosting options
Glovia is designed to run in a private cloud, on-premises, or an approved Saudi-region environment, subject to the deployment agreement. Provider, residency, and access are documented in the deployment schedule so data and compute stay inside the agreed boundary.
Data residency
Enterprise data is intended to remain in the client's selected region and tenancy. We do not use one customer's data to train models for another. Residency commitments for a given deployment are set in the commercial agreement.
Encryption
Data is protected in transit and at rest using industry-standard encryption. Key handling follows the deployment model, including customer-controlled options where the contract requires it.
Role-based access control
Access is granted by role, not by shared passwords. Administrators can limit who sees financials, operations, or board material, and can revoke access when people leave.
Audit logging
Sensitive actions are logged so security and internal audit can reconstruct who accessed what, and when. Logs are retained according to the client's policy and the deployment agreement.
Tenant isolation
Each client runs in an isolated tenancy. There is no shared data pool across customers. Compute can be dedicated per client so workloads do not mix.
Disaster recovery
Deployments are designed with backup, failover, and recovery patterns. Recovery time and point objectives are defined per client rather than as a single public SLA on this site.
NCA, SAMA, and NDMO alignment
The architecture is designed to support applicable NCA, SAMA, and NDMO controls; scope is agreed per deployment. For SAMA-regulated customers, control mapping is scoped against applicable SAMA Cyber Security Framework requirements. This is not a certification or regulator endorsement. Alignment is not the same as a regulator-issued certificate. Formal assessments, where required, are scoped in the engagement.
AI governance and explainability
Recommendations are meant to be inspectable: source context, decision trail, and the ability for executives to challenge an output. Glovia is decision support. Your organization remains accountable for the actions it takes.
Ask for the trust briefing.
We will walk through hosting, residency, and controls for your environment, without inflating what is certified.
Request an Executive Demo