Security & compliance · United Arab Emirates

Edrak and the UAE Cyber Security Council

The Cyber Security Council sets the UAE's national cybersecurity policy and standards. Edrak works inside the controls you already have: your permissions, your data location, and a record of everything it does.

CSC
National authority. Sets national cybersecurity policy and requirements.
Applies to
Federal government entities, critical sectors and the organisations that supply them across the UAE.
Where Edrak stands
Edrak maps its controls to the Council's national standards and shares the mapping with your team. The Council does not certify vendors.

The Council's frameworks

The national standard is the core requirement. Three related policies shape how an AI platform is deployed alongside it.

  • NCS

    National Cybersecurity Standard

    Governance, risk and security controls for federal entities and critical sectors.

  • Cloud

    Cloud Security Policy

    Requirements for cloud adoption, provider due diligence and data location.

  • IoT / OT

    IoT and Operational Technology Policy

    Security requirements for connected and industrial systems.

  • Emirate

    Emirate-level standards

    Dubai's ISR and Abu Dhabi's information security standard, which apply alongside federal policy.

How Edrak supports your CSC obligations

The obligations are yours. Edrak is built to make meeting them straightforward, and to be clear about what stays on your side.

  • Identity and access

    Edrak: Signs in through your identity provider and inherits the permissions people already hold. It cannot see data a user could not see.

    You: Identities, roles, and joiner, mover and leaver processes.

  • Data location

    Edrak: Runs in Edrak Cloud in your chosen region, in your own cloud account, or on-premises. Your data is used for your business only.

    You: Classifying data and choosing the deployment that fits each class.

  • Records

    Edrak: Every action, decision and outcome is logged: who asked, which model ran, what it touched, what came back.

    You: Retention periods and forwarding to your monitoring tools.

  • Models and third parties

    Edrak: Routing rules keep restricted data on open-weight models inside your boundary; hosted frontier models handle the rest.

    You: Approving which models may handle which classes of data.

  • Human oversight

    Edrak: Approval steps sit where you set them. Nothing completes without the sign-off you require.

    You: Defining the approval points and who holds them.

  • Incidents

    Edrak: A named security contact, notification commitments and support for your investigation, agreed in contract.

    You: Incident handling and reporting to the Council where required.

For your security and compliance teams

We share a requirement-by-requirement mapping to the CSC frameworks, a data-flow diagram for your deployment option, and our security overview, under NDA. We also answer questionnaire items directly.

Talk to our team

The Council issues requirements and guidance; it does not certify vendors. This page describes how Edrak's controls support your obligations. Edrak does not claim compliance or certification on your behalf. Confirm applicability with your compliance team.