Security & compliance

Built for regulated, audited environments.

Riyada Intelligence handles workforce, skills and compliance data for regulated enterprises. Here's how we protect it, and where we honestly stand on formal certification today.

SOC 2 Type II

In progress

SOC 2 Type II audit in progress. We're happy to share our current security controls and audit timeline on request.

GDPR

Aligned

Data subject rights, lawful basis for processing, and breach notification practices — see our Privacy Policy for the full detail.

ISO 27001

Planned

ISO 27001 certification is on our roadmap. Ask us for details on our current information security practices and certification plans.

Data residency

Region options planned

Data residency options (EU, UAE, and additional regions) are being finalized based on customer requirements. Talk to us about your specific residency needs.

Certification status shown for illustration — ask us for our current security documentation.

How we protect your data

Encryption

  • The site and API are served over HTTPS/TLS. We're closing a gap where a plain-HTTP request currently isn't force-redirected to HTTPS — tracked as an open item, not yet fixed.
  • Account passwords are never stored in plain text — only as salted, one-way hashes.
  • Encryption of data at rest depends on the underlying server/disk infrastructure rather than our own application-level encryption today — ask us for specifics if this matters for your evaluation.

Access control

  • Role-based permissions (learner, manager, org admin, compliance manager, and more) gate every action server-side, not just hidden in the UI.
  • Every request is scoped to a verified, signed session — there is no anonymous fallback that can expose another organisation's data.
  • Multi-tenant data is isolated per-request at the application layer. Database-level row-security policies also exist in the schema as an intended second layer; we're still finishing the work to have every database connection enforce them, so treat that layer as in progress, not yet a live backstop.

Data residency & hosting

  • Hosting region, backup frequency and retention details vary by deployment — talk to us and we'll walk you through what applies to your organisation.

Third-party learning providers

  • When your organisation connects a content provider (GO1 today, with more added as we grow), we share only what's needed to enroll a learner and record their progress and course completion back into your dashboards — not broader profile or workforce data.
  • Each connected provider processes that data under its own security and privacy terms — see our Privacy Policy for how this works.

Incident response & disclosure

If you believe you've found a security issue, email security@riyadaintel.com with details, or use the form below and mark it urgent. We don't yet have a published incident-response SLA; ask us directly for our current process.

For the full detail on what we collect, how it's used, and your rights over it, see our Privacy Policy and Terms of Service.

Need our full security documentation for procurement?

Tell us a bit about your organisation and we'll follow up with what your security or procurement team needs.

  • Tell us a bit about your organisation
  • We'll follow up with what your security or procurement team needs
  • No commitment to start the conversation