Trust, security, and data residency

What Naiza can say today about hosting, encryption, access, and product limits. This page is for procurement and security review. It is not a certification.

Hosting and residency

Naiza stores and processes product data in the Kingdom of Saudi Arabia. Fraud events, customer records used for decisions, and AML screening data used by the product stay in KSA. We do not publish a cloud-region SKU or a named certification on this page.

Encryption and access

Data in transit uses TLS. Data at rest uses industry-standard encryption. Access is limited with role-based controls, and API authentication uses API keys over encrypted connections. Details live in the privacy policy.

Retention and incidents

We retain account and service data while the account is active or as needed to provide the service, subject to legal retention duties. Security incidents are handled under applicable law. Contact support@naiza.ai for privacy or incident questions.

What this page does not claim

Naiza does not claim SAMA certification, NCA certification, PDPL certification, SOC 2, or ISO 27001 on this site. AML screening returns match context for your review workflow. It is not a legal determination that a person or entity is sanctioned.

Product limits to keep in the RFP

  • Fraud decisions depend on the events, identifiers, and rules you send. Observation mode is available before enforcement.
  • AML screens against OFAC SDN, UN Consolidated, EU sanctions, licensed Dow Jones, and OpenSanctions in one request. Entity counts are not published here.
  • Dow Jones adverse-media coverage is structured list data, not a promise that Naiza crawls the open web.
  • This is not a full transaction-monitoring suite. Case workflows exist for screening follow-up, not a replacement for your compliance program.

Review the product with your security team

Request a demo, read the privacy policy, or start with the API docs.