Security & compliance
Your data does not leave the Kingdom
Raseen was designed from the start to operate inside the Saudi regulatory framework, rather than adapted to fit it afterwards. This page explains how.
Where your data lives
Raseen deploys onto infrastructure you choose, not infrastructure we impose. You have three options:
- An approved Saudi cloud — with providers registered with the Communications, Space & Technology Commission, in the Riyadh or Jeddah regions.
- A private cloud — an isolated environment dedicated to your organisation alone.
- On your own premises — a full deployment on your servers, with no external dependency.
In-Kingdom is the default, with no cross-border transfer costs. Data is only processed outside the Kingdom if you explicitly choose global models for non-classified work — and that choice is yours to make or decline.
The regulations the design answers to
| Authority | Requirement | How Raseen addresses it |
|---|---|---|
| SDAIA — Personal Data Protection Law (PDPL) | Privacy and the right to erasure | Personal data is encrypted at field level. On an erasure request the encryption key is destroyed, making the data permanently unrecoverable. |
| National Data Management Office (NDMO) | Governance and data quality | Mandatory human review before any data enters the knowledge base, with an immutable audit log. |
| National Cybersecurity Authority (NCA) | Cybersecurity and access control | Network isolation of databases, AES-256 encryption, and role-based access controls. |
| Communications, Space & Technology Commission (CST) | Data localisation | Deployment exclusively within data centres located inside the Kingdom. |
Raseen is built to meet these requirements architecturally. Legal responsibility for the data remains with the organisation that owns it; we provide the controls that make meeting those obligations practical.
AI models
Not all data deserves the same treatment. The classification of the data decides the model, rather than the other way round. Raseen therefore operates at three levels, and the decision stays yours in every case:
- Global models for non-classified data — for work like drafting marketing content, analysing public data, or preparing correspondence, leading global models such as Anthropic's Claude, OpenAI's models, or Gemini can be used through enterprise tiers configured for zero data retention. You get the highest accuracy available without exposing sensitive material.
- Managed models inside a defined region — for internal operational data, models run within a specified geographic region under a contractual zero-retention policy, so neither inputs nor outputs are stored or used for training.
- Self-hosted open-source models — for sensitive and classified data, models run entirely inside your environment or a data centre within the Kingdom, so the data never leaves your network at all.
Every project begins by classifying your data before a model is chosen, and we document which category is processed at which level. In all cases, your organisation's data is not used to train any model — not ours, and not anyone else's.
No vendor lock-in
Raseen's architecture is portable between providers without re-engineering. If you decide to change cloud provider, the system moves with you. There is no forced dependency on a single vendor.