Security underpins everything we run — cloud hosting, business email, DNS and SSL for organizations across Saudi Arabia and the GCC. This page sets out the controls we operate and the Saudi frameworks our platform is built to align with.
Customer data — mailboxes, databases, DNS, account records — is hosted and backed up inside the Kingdom of Saudi Arabia (Riyadh). We do not ship customer content or backups to an off-shore provider. Data residency is a design constraint, not an afterthought — and it is what lets us serve PDPL-, CMA- and SAMA-sensitive customers.
TLS 1.2 and 1.3 only on all public endpoints; legacy TLS 1.0/1.1 refused; HSTS and modern security headers enforced.
We operate our own certificate issuance against a publicly-trusted CA; certificates auto-renew continuously so they never lapse.
SSL private keys are generated and stored on a dedicated, hardened hosting node — never on the mail or portal server.
Storage volumes are encrypted with AES-256 at the infrastructure layer; sensitive application fields are additionally encrypted; passwords use strong one-way hashing.
Two-factor authentication is required for every administrator — including tenant administrators — and available to all users.
Server access is SSH key-only; password authentication and direct root password login are disabled. Least-privilege roles and login rate-limiting throughout.
Each customer's data is isolated by explicit per-tenant scoping across mail, DNS and certificates, verified by an automated test suite.
Automated daily in-Kingdom backups (30-day retention) plus database binary logging for point-in-time recovery; destructive database commands are blocked in production.
Our platform is built to align with the Saudi cybersecurity and data-protection frameworks below. An internal automated compliance check verifies the technical controls on a regular cadence.
| Framework | What it covers | How we align |
|---|---|---|
| NCA ECC-2:2024 / ECC-1:2018 | Essential Cybersecurity Controls | Governance, IAM, cryptography, logging, backup, vulnerability & incident management. |
| NCA CCC-1:2020 | Cloud Cybersecurity Controls | Provider-side tenant isolation, key management, cloud-stack protection. |
| PDPL (SDAIA) | Personal Data Protection Law | Lawful basis & consent, data-subject rights, 72-hour breach notification, in-Kingdom residency. |
| CMA Cybersecurity Guidelines | Capital-market institutions | For regulated clients: KSA residency, tenant segregation, audit rights, certified deletion on exit. |
| SAMA Cyber Security Framework | Saudi Central Bank-regulated entities | Encryption, IAM/MFA, logging & ≥12-month retention, incident management, BCM, third-party & cloud controls, KSA data residency. |
We process personal data under the Saudi PDPL — see the privacy notice on our cloud portal at cloud.alskyline.com/privacy and the full security write-up at cloud.alskyline.com/trust. Our full PDPL / CMA / SAMA document set — DPA, sub-processors, data rights, retention, breach notification and consent — is in the Compliance Center. To report a security issue, contact security@alskyline.com; for privacy, privacy@alskyline.com.