Trust
Security and data residency
How customer data is hosted, segregated, encrypted and controlled, and what that means for buyers in the UAE and Saudi Arabia.
Last updated: July 31, 2026
Hosting and data residency
Data residency is usually the first question asked by regulated buyers in the UAE and Saudi Arabia, and it is a scoping decision rather than a single fixed answer. Platia 360 can be deployed so that customer data is held in a specified region, and the hosting region, deployment model and any in-country requirements are agreed and documented before implementation begins.
If your organisation is subject to sector rules on where data may be stored or processed, tell us during scoping. We will confirm in writing what is held, where it is held, who can access it and what leaves the environment.
Tenant segregation
Each customer's operational records are logically segregated. Access to a record is determined by the user's role and permissions inside their own tenant. Segregation and permission rules are enforced on the server, not only in the interface, so they cannot be bypassed by a modified client.
Access control
- Role-based permissions covering modules, records, fields and actions
- Least-privilege administrative access, reviewed as part of implementation
- Approval and workflow steps recorded against the user who performed them
- Audit history for changes to controlled records
Encryption
Data is encrypted in transit using current TLS. Data at rest is encrypted by the underlying hosting platform. Credentials and integration secrets are stored separately from application data and are never exposed in the interface or in exports.
Backups and continuity
Backup frequency, retention period and recovery objectives are agreed per deployment and confirmed in the implementation documentation. Restore procedures are tested as part of go-live rather than assumed.
Privacy and applicable law
Platia 360 LLC FZ is established in Dubai, U.A.E. Personal data handling is aligned to UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL). For Saudi deployments, handling is aligned to the Kingdom's Personal Data Protection Law and to applicable data classification and localisation expectations. Where a customer is itself a controller, responsibilities are set out in the agreement between us.
See also our Privacy Policy.
This website
This website is served over HTTPS with HSTS, a strict Content Security Policy and clickjacking protection. Forms are protected by Cloudflare Turnstile and rate limiting. The website does not use advertising or cross-site tracking cookies, and its analytics are first-party and do not profile individual visitors.
Certifications
Where a formal certification such as ISO/IEC 27001 or SOC 2 is required for your procurement process, raise it during scoping and we will confirm current status and timelines in writing rather than by implication.
Reporting a vulnerability
If you believe you have found a security issue affecting Platia 360 or this website, contact [email protected] with enough detail to reproduce it. Please allow us a reasonable period to investigate and remediate before any public disclosure.
Questions
Security questionnaires, due diligence requests and architecture reviews are welcome. Contact [email protected].