Security & compliance · United Arab Emirates
Edrak and the UAE Cyber Security Council
The Cyber Security Council sets the UAE's national cybersecurity policy and standards. Edrak works inside the controls you already have: your permissions, your data location, and a record of everything it does.
- CSC
- National authority. Sets national cybersecurity policy and requirements.
- Applies to
- Federal government entities, critical sectors and the organisations that supply them across the UAE.
- Where Edrak stands
- Edrak maps its controls to the Council's national standards and shares the mapping with your team. The Council does not certify vendors.
The Council's frameworks
The national standard is the core requirement. Three related policies shape how an AI platform is deployed alongside it.
NCS
National Cybersecurity Standard
Governance, risk and security controls for federal entities and critical sectors.
Cloud
Cloud Security Policy
Requirements for cloud adoption, provider due diligence and data location.
IoT / OT
IoT and Operational Technology Policy
Security requirements for connected and industrial systems.
Emirate
Emirate-level standards
Dubai's ISR and Abu Dhabi's information security standard, which apply alongside federal policy.
How Edrak supports your CSC obligations
The obligations are yours. Edrak is built to make meeting them straightforward, and to be clear about what stays on your side.
Identity and access
Edrak: Signs in through your identity provider and inherits the permissions people already hold. It cannot see data a user could not see.
You: Identities, roles, and joiner, mover and leaver processes.
Data location
Edrak: Runs in Edrak Cloud in your chosen region, in your own cloud account, or on-premises. Your data is used for your business only.
You: Classifying data and choosing the deployment that fits each class.
Records
Edrak: Every action, decision and outcome is logged: who asked, which model ran, what it touched, what came back.
You: Retention periods and forwarding to your monitoring tools.
Models and third parties
Edrak: Routing rules keep restricted data on open-weight models inside your boundary; hosted frontier models handle the rest.
You: Approving which models may handle which classes of data.
Human oversight
Edrak: Approval steps sit where you set them. Nothing completes without the sign-off you require.
You: Defining the approval points and who holds them.
Incidents
Edrak: A named security contact, notification commitments and support for your investigation, agreed in contract.
You: Incident handling and reporting to the Council where required.
For your security and compliance teams
We share a requirement-by-requirement mapping to the CSC frameworks, a data-flow diagram for your deployment option, and our security overview, under NDA. We also answer questionnaire items directly.
Talk to our teamThe Council issues requirements and guidance; it does not certify vendors. This page describes how Edrak's controls support your obligations. Edrak does not claim compliance or certification on your behalf. Confirm applicability with your compliance team.

