Trust

Security at Waaqi

We help organizations run their compliance programs and we hold ourselves to the same standards. Here's how we protect your data.

Encryption Everywhere

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Secrets and keys are managed in dedicated key management services with strict access controls.

Identity & Access

Role-based access control, SSO, and multi-factor authentication. Tenant isolation ensures your data is logically segregated from every other customer.

Regional Hosting

Customer data is hosted in regional cloud infrastructure (UAE, KSA) to support data residency and sovereignty obligations.

Continuous Monitoring

24/7 logging, anomaly detection, and alerting across application, infrastructure, and identity layers.

Compliance Aligned

Operations aligned with ISO 27001, ADHICS, NCA, SAMA CSF, and UAE/KSA PDPL. Independent assessments performed regularly.

Vulnerability Management

Dependency scanning, static analysis, regular penetration testing, and a defined patch management process for critical vulnerabilities.

Secure Development

Secure SDLC with peer code review, automated tests, least-privilege CI/CD, and segregation of production and non-production environments.

Resilience & Backups

Encrypted backups, defined RPO/RTO, and tested disaster recovery procedures to keep your compliance program running.

Data Protection

Customer Content is treated as confidential and processed only to deliver the Services. AI features operate on your tenant data and are not used to train foundation models. Data export and deletion are supported per contractual terms.

Sub-processors

We engage a limited set of vetted sub-processors for cloud hosting, AI inference, monitoring, and support tooling, each bound by contractual confidentiality and security obligations. A current list is available on request.

Incident Response

Waaqi maintains a documented incident response plan with defined severities, on-call rotation, customer notification timelines, and post-incident review. Confirmed incidents impacting customer data are communicated to affected customers without undue delay.

Responsible Disclosure

If you believe you have discovered a security vulnerability in Waaqi, please report it to security@waaqi.ai. We appreciate responsible disclosure and will acknowledge reports promptly.

Security questions or assessment requests: security@waaqi.ai