Your invoices never leave the Kingdom.
Invoice content, clearance responses and the audit trail are stored and processed in Saudi Arabia. Where a supporting service sits outside it, it is named in the Privacy Policy, covered by a transfer safeguard, and never handed invoice content.
What actually protects the records.
Six controls, each of which we could be asked to demonstrate. None of them is a certificate we are hoping to earn.
Encrypted in transit and at rest
TLS 1.2 or better on every connection, including the one to ZATCA. Stored data and backups are encrypted with AES-256, with keys held in a managed key service.
Your stamp stays yours
Cryptographic stamp identifiers and their private keys are stored encrypted, isolated per tenant, and used only to sign your own invoices. They are never exported, shared or reused across customers.
Least privilege, logged
Staff access is role-based, granted only for a named reason, and requires multi-factor authentication. Every administrative action against customer data is logged and retained.
Tamper-evident by construction
Every invoice is hashed and chained to the one before it, exactly as ZATCA requires. An altered or missing invoice breaks the chain, which is detectable rather than deniable.
Retained for six years, then gone
Invoices are kept for the statutory retention period and exportable throughout it. Beyond that, and after your account closes, data is deleted on a defined schedule rather than kept indefinitely.
Backed up and restorable
Encrypted backups run continuously and restores are rehearsed, not assumed. A backup nobody has ever restored from is a filing cabinet, not a recovery plan.
We acknowledge within one business day and aim to give you a remediation timeline within five. We will not take legal action against research carried out in good faith.
- Do not access data that is not yours.
- Do not degrade the service for anyone else.
- Give us a reasonable window before publishing.
If a personal-data breach occurs and is likely to cause serious harm, we notify the Saudi Data & AI Authority within the period the Personal Data Protection Law requires, and affected customers without undue delay — what happened, what data was involved, what we have done, and what you should do.
Two things worth saying out loud.
What we do not claim
We do not currently hold a SOC 2 or ISO 27001 certificate, and we would rather say so than imply one. If your procurement process requires an independent attestation, contact us and we will tell you where that work stands rather than what we hope it will say.
Your side of it
- Use a unique password and turn on multi-factor authentication for every user.
- Remove users who leave. A key belonging to someone who no longer works for you is the most common way an account is compromised.
- Treat API keys as credentials: rotate them on a schedule and never commit them to a repository.