Compliance
Built for organizations that need AI to operate within clear rules.
Edrak is designed to support enterprise AI adoption within a structured legal, regulatory, and governance framework. That includes clear contractual commitments, controlled data handling, security measures, and product design choices intended to help customers meet internal and external compliance requirements.
Compliance at a glance
Designed for regulated environments
Edrak is built to support organizations that need visibility, control, and accountable use of AI.
Saudi-first legal alignment
Edrak is designed with the legal and regulatory context of the Kingdom of Saudi Arabia in mind, including local data handling expectations and hosting needs.
Contract-backed commitments
Customer protections are supported through contractual documents, including service terms, privacy and data handling commitments, and related enterprise documentation.
Governance by design
Edrak provides administrative controls, access management, and workspace-level visibility to support internal compliance and policy enforcement.
Enterprise diligence support
Security questionnaires, architecture reviews and documentation requests are supported during enterprise evaluation.
Security overview
Security is the shape of the system, not a feature.
Agents inherit your permissions, act only where authorized, and leave a record of everything they touch. The same controls apply to every person, every agent and every action, on every deployment.
Identity and access
Agents see exactly what the person they work for may see. Access is evaluated per retrieval, never cached into the answer, and write access is scoped per workflow and granted explicitly.
Data protection
Encryption applies in transit and at rest on every deployment shape. Sensitive fields are masked before inference, per data class.
Residency and deployment
Data and inference run on infrastructure in the jurisdiction you designate, and model routing respects residency and data classification before fit, cost or speed. Managed cloud, regulation-ready configurations designed to meet GDPR, PDPL and sector rules, and fully isolated sovereign or air-gapped deployment are available per engagement.
Auditability
An immutable audit log holds what ran, under whose authority, on which evidence, with what result. Exportable to your SIEM.
Human controls
You define what AI does alone and what waits for approval. Missions pause at those lines, and work resumes the moment the owner decides.
Spend controls
Budgets and limits apply per workflow, team and department, observable per task. Runaway loops stop at the boundary.