Skip to content
GloviaGlovia.

Security & Trust

Security
you can inspect.

What is available today, what is designed to support regulatory requirements, what is planned, and certifications published only after they are issued.

Enterprise buyers should not have to guess: what is available today, what is designed for compliance, what is planned, and what is independently certified.

Currently available

Capabilities in the platform architecture and typical deployments.

  • Private cloud or on-premise hosting
  • Saudi-region deployment options configurable by agreement (provider, residency, and access documented in the deployment schedule)
  • End-to-end encryption
  • Role-based access control
  • Audit logging
  • Tenant isolation. No cross-customer data sharing
  • Dedicated AI compute per client
  • Disaster recovery and failover patterns
  • AI decision audit trail

Compliance-aligned design

Controls and patterns designed to support these frameworks. Not a certification claim.

  • Zero Trust architecture
  • SOC 2-aligned control design
  • ISO 27001-aligned control design
  • Designed to support applicable controls at relevant regulators, scoped per engagement. This does not mean certification or endorsement by any regulator.

Planned

Intended attestations and publications. Not yet complete.

  • Independent SOC 2 Type II report
  • ISO 27001 certification
  • Public summary of third-party audit results

Certifications obtained

Only independent attestations already issued appear here.

None published yet. We will list SOC 2, ISO 27001, or equivalent reports here only after they are officially obtained.

Controls

How trust is designed in.

01

Hosting options

Glovia is designed to run in a private cloud, on customer premises (on-premises), or an approved Saudi-region environment, subject to the deployment agreement. Provider, residency, and access are documented in the deployment schedule so data and compute stay inside the agreed boundary.

02

Data residency

Enterprise data is intended to remain in the client's selected region and tenancy. We do not use one customer's data to train models for another. Residency commitments for a given deployment are set in the commercial agreement.

03

Encryption

Data is protected in transit and at rest using industry-standard encryption. Key handling follows the deployment model, including customer-controlled options where the contract requires it.

04

Role-based access control

Access is granted by role, not by shared passwords. Administrators can limit who sees financials, operations, or board material, and can revoke access when people leave.

05

Audit logging

Sensitive actions are logged so security and internal audit can reconstruct who accessed what, and when. Logs are retained according to the client's policy and the deployment agreement.

06

Tenant isolation

Each client runs in an isolated tenancy. There is no shared data pool across customers. Compute can be dedicated per client so workloads do not mix.

07

Disaster recovery

Deployments are designed with backup, failover, and recovery patterns. Recovery time and point objectives (RTO/RPO) and service levels are defined per deployment agreement rather than as a single public SLA on this site.

08

Regulatory alignment

The architecture is designed to support applicable controls at the National Cybersecurity Authority (NCA), the Saudi Central Bank (SAMA), the Saudi Data and AI Authority — SDAIA (SDAIA), and the National Data Management Office (NDMO); scope is agreed per deployment. For SAMA-regulated customers, control mapping is scoped against applicable SAMA Cyber Security Framework requirements. This is not a certification or regulator endorsement, and formal assessments are scoped within each engagement.

09

AI governance and explainability

Recommendations are meant to be inspectable: source context, decision trail, and the ability for executives to challenge an output. Glovia is decision support. Your organization remains accountable for the actions it takes.

10

Security contact and vulnerability disclosure

Report security issues to hello@glovia.ai. Coordinated disclosure expectations are published at /.well-known/security.txt.

11

Incident notification

We notify the customer without undue delay of security incidents affecting their deployment, in accordance with the commercial agreement.

12

Sub-processors for the public website

Website and inquiry handling currently involves Vercel (hosting), Calendly (optional scheduling), and the configured SMTP host for outbound email — as described in the Privacy Notice.

13

Data return and deletion

On termination of a contracted deployment, customer data return and deletion follow the commercial agreement and any data processing terms.

14

Data processing agreement

A data processing agreement (DPA) is available on request for enterprise engagements.

Ask for the trust briefing.

We will walk through hosting, residency, and controls for your environment, without inflating what is certified.

Request an Executive Demo