Skyline Solutions

Security & Compliance

Security underpins everything we run — cloud hosting, business email, DNS and SSL for organizations across Saudi Arabia and the GCC. This page sets out the controls we operate and the Saudi frameworks our platform is built to align with.

Last reviewed: 26 Jul 2026 · Riyadh, Kingdom of Saudi Arabia
NCA ECC-2:2024NCA Cloud Controls (CCC)PDPL (SDAIA)CMA GuidelinesSAMA CSF
Get browser-trusted SSL →

In-Kingdom by design

Customer data — mailboxes, databases, DNS, account records — is hosted and backed up inside the Kingdom of Saudi Arabia (Riyadh). We do not ship customer content or backups to an off-shore provider. Data residency is a design constraint, not an afterthought — and it is what lets us serve PDPL-, CMA- and SAMA-sensitive customers.

Encryption & certificates

In transit

TLS 1.2 and 1.3 only on all public endpoints; legacy TLS 1.0/1.1 refused; HSTS and modern security headers enforced.

alskyline SSL

We operate our own certificate issuance against a publicly-trusted CA; certificates auto-renew continuously so they never lapse.

Private-key isolation

SSL private keys are generated and stored on a dedicated, hardened hosting node — never on the mail or portal server.

At rest

Storage volumes are encrypted with AES-256 at the infrastructure layer; sensitive application fields are additionally encrypted; passwords use strong one-way hashing.

Access control & resilience

Mandatory admin 2FA

Two-factor authentication is required for every administrator — including tenant administrators — and available to all users.

Key-only infrastructure

Server access is SSH key-only; password authentication and direct root password login are disabled. Least-privilege roles and login rate-limiting throughout.

Tenant isolation

Each customer's data is isolated by explicit per-tenant scoping across mail, DNS and certificates, verified by an automated test suite.

Backups & recovery

Automated daily in-Kingdom backups (30-day retention) plus database binary logging for point-in-time recovery; destructive database commands are blocked in production.

Framework alignment

Our platform is built to align with the Saudi cybersecurity and data-protection frameworks below. An internal automated compliance check verifies the technical controls on a regular cadence.

FrameworkWhat it coversHow we align
NCA ECC-2:2024 / ECC-1:2018Essential Cybersecurity ControlsGovernance, IAM, cryptography, logging, backup, vulnerability & incident management.
NCA CCC-1:2020Cloud Cybersecurity ControlsProvider-side tenant isolation, key management, cloud-stack protection.
PDPL (SDAIA)Personal Data Protection LawLawful basis & consent, data-subject rights, 72-hour breach notification, in-Kingdom residency.
CMA Cybersecurity GuidelinesCapital-market institutionsFor regulated clients: KSA residency, tenant segregation, audit rights, certified deletion on exit.
SAMA Cyber Security FrameworkSaudi Central Bank-regulated entitiesEncryption, IAM/MFA, logging & ≥12-month retention, incident management, BCM, third-party & cloud controls, KSA data residency.
An honest note on certification. The controls above describe genuine, operating measures and our alignment with these frameworks. Alignment is not the same as a formal certification or audit attestation, which is issued by the respective authority. We are happy to support due-diligence reviews under NDA.

Privacy & reporting

We process personal data under the Saudi PDPL — see the privacy notice on our cloud portal at cloud.alskyline.com/privacy and the full security write-up at cloud.alskyline.com/trust. Our full PDPL / CMA / SAMA document set — DPA, sub-processors, data rights, retention, breach notification and consent — is in the Compliance Center. To report a security issue, contact security@alskyline.com; for privacy, privacy@alskyline.com.