Trust
Security and data residency
How customer data is hosted, segregated, encrypted and controlled, and what that means for buyers in the UAE and Saudi Arabia.
Last updated: July 31, 2026
Hosting and data residency
Data residency is usually the first question asked by regulated buyers in the UAE and Saudi Arabia, and it is a scoping decision rather than a single fixed answer. Platia 360 can be deployed so that customer data is held in a specified region, and the hosting region, deployment model and any in-country requirements are agreed and documented before implementation begins.
If your organisation is subject to sector rules on where data may be stored or processed, tell us during scoping. We will confirm in writing what is held, where it is held, who can access it and what leaves the environment.
Tenant segregation
Each customer's operational records are logically segregated. Access to a record is determined by the user's role and permissions inside their own tenant. Segregation and permission rules are enforced on the server, not only in the interface, so they cannot be bypassed by a modified client.
Access control
- Role-based permissions covering modules, records, fields and actions
- Least-privilege administrative access, reviewed as part of implementation
- Approval and workflow steps recorded against the user who performed them
- Audit history for changes to controlled records
Encryption
Data is encrypted in transit using current TLS. Data at rest is encrypted by the underlying hosting platform. Credentials and integration secrets are stored separately from application data and are never exposed in the interface or in exports.
Backups and continuity
Backup frequency, retention period and recovery objectives are agreed per deployment and confirmed in the implementation documentation. Restore procedures are tested as part of go-live rather than assumed.
Privacy and applicable law
Platia 360 LLC FZ is established in Dubai, U.A.E. Personal data handling is aligned to UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL). For Saudi deployments, handling is aligned to the Kingdom's Personal Data Protection Law and to applicable data classification and localisation expectations. Where a customer is itself a controller, responsibilities are set out in the agreement between us.
See also our Privacy Policy.
This website
This website is served over HTTPS with HSTS, a strict Content Security Policy and clickjacking protection. Forms are protected by Cloudflare Turnstile and rate limiting. The website does not use advertising or cross-site tracking cookies, and does not profile individual visitors.
Certifications
Where a formal certification such as ISO/IEC 27001 or SOC 2 is required for your procurement process, raise it during scoping and we will confirm current status and timelines in writing rather than by implication.
Reporting a vulnerability
If you believe you have found a security issue affecting Platia 360 or this website, contact info@platia360.com with enough detail to reproduce it. Please allow us a reasonable period to investigate and remediate before any public disclosure.
Questions
Security questionnaires, due diligence requests and architecture reviews are welcome. Contact info@platia360.com.
Common questions
Questions buyers ask about Security and data residency
Where is customer data hosted, and can it stay in the UAE or Saudi Arabia?
Hosting region and deployment model are a scoping decision rather than one fixed answer. Platia 360 can be deployed so that customer data is held in a specified region, including in-country hosting for the UAE and Saudi Arabia. What is held, where it is held, who can access it and what leaves the environment is confirmed in writing before implementation begins.
How is our data kept separate from other customers?
Each customer's operational records are logically segregated, and access to any record is determined by the user's role and permissions within their own tenant. Segregation and permission rules are enforced on the server rather than only in the interface, so a modified client cannot bypass them.
Does Platia 360 hold ISO 27001 or SOC 2 certification?
Where a formal certification such as ISO/IEC 27001 or SOC 2 is required for your procurement process, raise it during scoping and we will confirm current status and timelines in writing rather than by implication. Security questionnaires, due diligence requests and architecture reviews are welcome.
What happens to data in transit and at rest?
Data is encrypted in transit using current TLS, and at rest by the underlying hosting platform. Credentials and integration secrets are stored separately from application data and are never exposed in the interface or in exports.
How are backups and recovery handled?
Backup frequency, retention period and recovery objectives are agreed per deployment and recorded in the implementation documentation. Restore procedures are tested as part of go-live rather than assumed to work.
Which privacy laws apply?
Platia 360 LLC FZ is established in Dubai. Personal data handling is aligned to UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, and for Saudi deployments to the Kingdom's Personal Data Protection Law and applicable data classification and localisation expectations. Where the customer is itself a controller, responsibilities are set out in the agreement between us.