Security and hosting
Hosted in the Kingdom
The platform is hosted in the Kingdom, designed with NCA and SDAIA requirements in consideration.
The entity's data stays in the Kingdom
Data belonging to entities using the EASPM platform is hosted inside the Kingdom of Saudi Arabia, and so are its backups.
Enquiries submitted through this site are separate. They are stored in our customer relationship system, which is hosted inside the Kingdom, and whose backups are replicated by the provider to data centres in Europe and Canada.
Every entity has a separate environment with its own data, configuration and branding, and no entity's data is shared with another in any form.
What we build into every environment
- Data isolation
- A separate environment per entity, and row-level permissions within an environment.
- Identity and access
- Single sign-on support connected to the entity's directory, reviewable roles and permissions, and a way to review what each role sees.
- Encryption
- Data encrypted in transit and at rest.
- Audit logging
- A complete record of every change: who, when, and what it was before and after, with a security event log.
- Backup and recovery
- Regular backups with published recovery objectives, stated in the service level agreement.
- Personal data protection
- Personal data processed in accordance with the Personal Data Protection Law, with the basis of processing documented and a consent record kept.
- Secure integration
- APIs with dedicated keys and limited permissions; credentials never reach the browser.
- Testing
- Independent penetration testing before public launch, with findings fixed before go-live.
No certificate before it is issued
EASPM makes no claim of certification, accreditation or attested compliance from any regulator unless the certificate has actually been issued. When one is, it is published with its date and reference on the local content page.
If your entity has specific security or contractual requirements, we go through them item by item in the demo session or through contact.
Reporting a vulnerability
If you discover a vulnerability in the platform or this site, write to info@etharien.com. We acknowledge the report, treat it seriously, and take no action against anyone who reports in good faith.
Technical questions before buying?
We answer them item by item with your IT team.