Trust · Security
Security readiness
What is live today, what is planned, and nothing in between.
Controls are listed in their real state. A control is either live on what is actually deployed, or planned and not yet built.
The reference framework is the Saudi Central Bank's Cyber Security Framework. Full compliance with it is required before carrying on any activity; this page is a record of progress towards it, not a claim to hold it.
Last updated: 9 September 2026
Controls
- Transport encryptionLive today
All traffic over HTTPS, with forced redirection from HTTP and an HSTS policy.
- Security headersLive today
Frame-embedding denied, MIME sniffing blocked, a restricted referrer policy, and a permissions policy that turns off camera, microphone and location.
- Data minimisationLive today
The marketing site stores no personal data at the edge. What you type into a form is all that reaches us.
- Secret isolationLive today
Service keys live in server-side environment variables. No privileged key is sent to the browser.
- Content security policyPlanned
No content security policy header is sent today. A policy with an allow-list of script and style sources comes before any form handles customer data.
- Automated-submission defencePlanned
Cloudflare Turnstile on every form, with per-address rate limiting.
- Multi-factor authenticationPlanned
Mandatory on every administrative account and on the customer portal before it holds any customer data.
- Audit loggingPlanned
Append-only logging of every access to personal or financial data, with a stated retention period.
- Web application firewallPlanned
Firewall rules in front of the APIs, blocking common attack patterns, with continuous monitoring.
- Independent penetration testPlanned
A third-party test before applying to the regulatory testing environment. It has not been carried out as of the date on this page.
- Vulnerability managementPlanned
Automated dependency scanning, with published deadlines to close findings by severity.
- Business continuity and recoveryPlanned
Encrypted backups inside the Kingdom, restore testing on a schedule, and recovery time objectives: [TODO]
- Incident responsePlanned
A written response plan, and notification of the competent authorities and affected data subjects within the statutory deadlines.
Where the data sits
The requirement: customer and financial data is stored and processed inside the Kingdom, and so are its backups and its recovery environment.
Today: the site runs on Cloudflare's edge network and holds no personal data there. Form submissions and accounts are written to a Neon database in Frankfurt, Germany, outside the Kingdom.
Before launch: all personal and financial data moves to in-Kingdom infrastructure, is deleted from any external store, and the move is recorded in the processing register.
What we do not claim
- We hold no ISO 27001 certificate and no SOC 2 report.
- No independent security audit and no penetration test has been carried out as of the date on this page.
- There is no certified information security management system today. When there is, it will be named here with the issuing body, the date, and its scope.
Reporting a vulnerability
If you find a vulnerability, write to us before publishing it: [TODO]
We acknowledge within two working days. We take no action against good-faith security research that avoids other people's data and does not disrupt the service.
PGP key and security.txt: [TODO]