Security & compliance · Qatar

Edrak and the National Cyber Security Agency

The NCSA sets Qatar's cybersecurity requirements and maintains the National Information Assurance standard. Edrak works inside your existing controls: your permissions, your data location, and a record of everything it does.

NCSA
National authority. Sets Qatar's cybersecurity requirements, including the National Information Assurance standard.
Applies to
Government entities, critical sectors and the organisations that supply them in Qatar.
Where Edrak stands
Edrak maps its controls to the NCSA's National Information Assurance requirements and shares the mapping with your team. The NCSA does not certify vendors.

The NCSA frameworks

The National Information Assurance standard is the core requirement. Three related policies shape how an AI platform is deployed alongside it.

  • NIA

    National Information Assurance Policy

    Governance, risk, security controls and assurance for information systems in Qatar.

  • Cloud

    National Cloud Security Policy

    Requirements for cloud adoption, provider due diligence and data location.

  • Data

    National Data Classification Policy

    Classification scheme and handling rules across the data lifecycle.

  • Critical

    Critical Information Infrastructure Protection

    Additional protections for systems supporting critical sectors.

How Edrak supports your NCSA obligations

The obligations are yours. Edrak is built to make meeting them straightforward, and to be clear about what stays on your side.

  • Identity and access

    Edrak: Signs in through your identity provider and inherits the permissions people already hold. It cannot see data a user could not see.

    You: Identities, roles, and joiner, mover and leaver processes.

  • Data location

    Edrak: Runs in Edrak Cloud in your chosen region, in your own cloud account, or on-premises. Your data is used for your business only.

    You: Classifying data and choosing the deployment that fits each class.

  • Data classification

    Edrak: Routing and deployment rules are set per classification level, so restricted data never reaches a model or location you have not approved.

    You: Classifying data under the national scheme.

  • Records

    Edrak: Every action, decision and outcome is logged: who asked, which model ran, what it touched, what came back.

    You: Retention periods and forwarding to your monitoring tools.

  • Models and third parties

    Edrak: Routing rules keep restricted data on open-weight models inside your boundary; hosted frontier models handle the rest.

    You: Approving which models may handle which classes of data.

  • Incidents

    Edrak: A named security contact, notification commitments and support for your investigation, agreed in contract.

    You: Incident handling and reporting to the NCSA where required.

For your security and compliance teams

We share a requirement-by-requirement mapping to the NCSA frameworks, a data-flow diagram for your deployment option, and our security overview, under NDA. We also answer questionnaire items directly.

Talk to our team

The NCSA issues requirements and guidance; it does not certify vendors. This page describes how Edrak's controls support your obligations. Edrak does not claim compliance or certification on your behalf. Confirm applicability with your compliance team.