TrustRegulatory alignment

Built for regulated Saudi environments.

Controls, deployment and evidence for your obligations.

Xybern is designed for deployment in regulated Saudi environments. It provides the authorisation controls, deployment options and cryptographic provenance that let a regulated organisation meet its own obligations under the frameworks that bind it. Xybern holds no certification and claims none.

Frameworks Xybern is built to support.

For each framework, Xybern maps the applicable controls to product capabilities, deployment options and the evidence a reviewer can check. The obligation stays with the regulated organisation; Xybern gives it the means to meet it.

SAMA CSF v1.0

Cyber Security Framework

Product controls, eleven policies and five registers, a per-subdomain self-assessment and a Vendor Assurance Pack mapped to the framework, plus a deployment-model note for the 3.4 vendor requirements that flow down to suppliers.

NCA ECC

Essential Cybersecurity Controls

Mapped control by control across the applicable domains, with the evidence for each control referenced in the control matrix.

NCA CCC-1:2020

Cloud Cybersecurity Controls

Tenant-side domains mapped to Xybern controls, with Saudi Private hosted on CST-registered OCI and Sovereign running inside your own cloud.

NCA DCC-1:2022

Data Cybersecurity Controls

Residency mandates, classification-aware rules, data minimisation, retention purge, certified deletion and encryption, mapped to the data lifecycle.

PDPL

Personal Data Protection Law and Transfer Regulation

Saudi identifier detection, residency and external-model mandates, retention and deletion, and deployment models that keep personal data in-Kingdom or within your boundary.

SDAIA

AI Ethics, Generative AI and AI Adoption Framework

Each expectation mapped to a Xybern control and its evidence, with an honest account of what Xybern does and does not do.

Sector regulators

Insurance Authority, CMA, CST, MoH, CCHI

The Saudi Insurance pack cites the Insurance Authority and CCHI, and the cyber annexes derive from the NCA ECC mapping. Per-sector citations are added as customers require them.

CST cloud regulations

Cloud operator disclosure

Saudi Private runs on CST-registered OCI, with Xybern disclosed as the operator in the Deployment Manifest and in the contract.

What is in the product.

These are controls a reviewer can verify, not statements on a page. Every one produces authorisation decisions or cryptographic evidence you can export.

Where your data lives.

Residency follows the deployment model. Xybern Cloud runs the managed platform, Dedicated (Saudi Private) keeps your environment in-Kingdom on CST-registered OCI, and Sovereign runs inside infrastructure you control, with your own keys. See the deployment models for the full comparison.

Deployment models

Deploying in a regulated Saudi environment?

Tell us which frameworks bind you, and we will map them to the controls, deployment model and evidence you need.