Security & compliance · Qatar
Edrak and the National Cyber Security Agency
The NCSA sets Qatar's cybersecurity requirements and maintains the National Information Assurance standard. Edrak works inside your existing controls: your permissions, your data location, and a record of everything it does.
- NCSA
- National authority. Sets Qatar's cybersecurity requirements, including the National Information Assurance standard.
- Applies to
- Government entities, critical sectors and the organisations that supply them in Qatar.
- Where Edrak stands
- Edrak maps its controls to the NCSA's National Information Assurance requirements and shares the mapping with your team. The NCSA does not certify vendors.
The NCSA frameworks
The National Information Assurance standard is the core requirement. Three related policies shape how an AI platform is deployed alongside it.
NIA
National Information Assurance Policy
Governance, risk, security controls and assurance for information systems in Qatar.
Cloud
National Cloud Security Policy
Requirements for cloud adoption, provider due diligence and data location.
Data
National Data Classification Policy
Classification scheme and handling rules across the data lifecycle.
Critical
Critical Information Infrastructure Protection
Additional protections for systems supporting critical sectors.
How Edrak supports your NCSA obligations
The obligations are yours. Edrak is built to make meeting them straightforward, and to be clear about what stays on your side.
Identity and access
Edrak: Signs in through your identity provider and inherits the permissions people already hold. It cannot see data a user could not see.
You: Identities, roles, and joiner, mover and leaver processes.
Data location
Edrak: Runs in Edrak Cloud in your chosen region, in your own cloud account, or on-premises. Your data is used for your business only.
You: Classifying data and choosing the deployment that fits each class.
Data classification
Edrak: Routing and deployment rules are set per classification level, so restricted data never reaches a model or location you have not approved.
You: Classifying data under the national scheme.
Records
Edrak: Every action, decision and outcome is logged: who asked, which model ran, what it touched, what came back.
You: Retention periods and forwarding to your monitoring tools.
Models and third parties
Edrak: Routing rules keep restricted data on open-weight models inside your boundary; hosted frontier models handle the rest.
You: Approving which models may handle which classes of data.
Incidents
Edrak: A named security contact, notification commitments and support for your investigation, agreed in contract.
You: Incident handling and reporting to the NCSA where required.
For your security and compliance teams
We share a requirement-by-requirement mapping to the NCSA frameworks, a data-flow diagram for your deployment option, and our security overview, under NDA. We also answer questionnaire items directly.
Talk to our teamThe NCSA issues requirements and guidance; it does not certify vendors. This page describes how Edrak's controls support your obligations. Edrak does not claim compliance or certification on your behalf. Confirm applicability with your compliance team.

