Security

How we protect your books.

Sakb holds the financial records of Saudi businesses. We treat that responsibility with the seriousness it deserves. This page explains, in plain terms, how your data is protected.

Last updated · 04 May 2026Version · 0.1 DRAFT

Draft — pending legal review

This page is a working draft. Its wording is not final and is being reviewed before launch.

Full draft in legal-drafts/01-security-DRAFT.md

Overview

Sakb holds the financial books of Saudi businesses. We treat that responsibility with the seriousness it deserves. This page describes, in plain terms, the controls in place to keep your data confidential, available, and intact.

Where we cite specific certifications, retention windows, or vendor names, those values are placeholders pending verification.

Data residency

Customer data is stored in Google Cloud's Saudi Arabia region (Dammam). Data does not leave the region for storage. Backups are kept in the same region.

Cross-border processing is limited to operational needs (e.g., the ML inference path for some agent workflows) and is disclosed in the subprocessor list below.

Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Database-level encryption is provided by the Google Cloud SQL service. Application-level encryption is applied to particularly sensitive fields (e.g., bank credentials, government IDs).

Keys are managed through Google Cloud KMS, with rotation and access logging enabled. Key rotation cadence: 90 days.

Access control

Customer data is accessible only by Sakb personnel with a documented operational need, and only via authenticated systems that log all access. All accounts use SSO with hardware MFA. There are no shared credentials.

Customer-side, Sakb supports per-user roles, granular permissions on accounting objects, and SSO integrations for Growth and Enterprise tiers.

Auditability

Every entry posted to a Sakb ledger has an immutable audit record: who (or which agent) created it, when, and on the basis of what supporting document. Audit records are retained for the life of the account plus the regulatory minimum.

Customers can export their full audit trail at any time. Auditors and external reviewers can be granted scoped, read-only access via a dedicated reviewer role.

Continuity & recovery

Backups are taken continuously and verified daily. Recovery point objective (RPO): 15 minutes. Recovery time objective (RTO): 4 hours.

Backup restoration is tested quarterly. Backup retention is 35 days for point-in-time recovery, plus monthly snapshots retained for the regulatory minimum.

Subprocessors

Sakb uses a small number of subprocessors to deliver the service. The current list, including the data each receives and the region in which it processes, is maintained in the subprocessor disclosure document available on request and published here at GA.

Incident response

Sakb maintains a 24/7 on-call rotation for security incidents affecting customer data. In the event of a confirmed incident, affected customers are notified within 72 hours and provided with a written post-incident report once the investigation is complete.

The response process is aligned with Saudi regulatory notification requirements where applicable.

Contact

Questions, audit requests, or to report a vulnerability: security@sakb.sa.

We use necessary cookies and local storage to remember your language and preferences, in line with the Saudi Personal Data Protection Law (PDPL). Privacy policy