OAT's data protection program is engineered for sovereign AI workloads — combining KSA residency, regulator-aligned governance, and enterprise security controls.
Processing aligned with the Saudi Personal Data Protection Law and SDAIA executive regulations.
Personal and enterprise data is hosted within KSA, on infrastructure under Saudi jurisdiction.
AES-256 at rest and TLS 1.3 in transit across all OAT services, with HSM-backed key management.
Zero-trust identity, least-privilege RBAC, MFA enforcement, and continuous session attestation.
Immutable, tamper-evident logs covering all data access and administrative actions.
Strict vetting, contractual safeguards, and ongoing monitoring of every sub-processor in the chain.
Defined incident severity matrix and 72-hour regulator notification commitment for qualifying incidents.
Standardized intake for access, correction, deletion, and portability requests with SLA timelines.
For data protection inquiries, DSR requests, or breach notifications, contact our Data Protection Office: