Security & sovereignty

Sovereign AI, the way the GCC needs it

Enterprise data belongs in the enterprise. Natiq supports deployment models for organizations that need control over data residency, model exposure, and infrastructure boundaries.

VPC deployment

Deploy the full Natiq runtime — Hyper Human orchestration, RAG index, and integrations — completely within your own Virtual Private Cloud. Nothing leaves your network boundary.

Self-hosted architecture

For ministries and regulated institutions: run Natiq on your own metal. Total data isolation with the same one-click template deployment experience.

Zero shared training

Your proprietary data never trains shared public models. Your private index stays private — encrypted at rest and in transit.

In-Kingdom residency

Hosting in Saudi data regions from day one, with NCA CCC-2 alignment baked into the reference architecture.

Deployment options

CapabilityShared cloudDedicated VPCSelf-hosted
Provisioning timeMinutesHoursDays
Data residencyKSA regionYour VPCYour data center
Network isolationNamespace + quotasDedicated node poolsAir-gap capable
Compliance postureSOC 2 / GDPRNCA CCC-2 alignedFull sovereign control
Best forStartups & SMBsEnterpriseGovernment & regulated

Controls

The concrete list, so a security reviewer can work through it rather than infer it from adjectives.

Encryption

  • TLS 1.2+ in transit on every channel, including the WhatsApp and voice legs.
  • AES-256 at rest for the knowledge index, transcripts, and configuration.
  • Customer-managed keys available on dedicated VPC and self-hosted deployments.

Isolation

  • Shared cloud: per-tenant namespace, quotas, and a logically separated knowledge index.
  • Dedicated VPC: single tenant, dedicated node pools, inside your own cloud account.
  • Self-hosted: your data centre, your security perimeter, air-gap capable.

Access control

  • Role-based access control over agents, knowledge sources, and connector credentials.
  • SSO and SCIM provisioning for enterprise deployments.
  • Scoped, revocable connector credentials — an agent only reaches the systems you grant it.

Auditability

  • Full audit trail of every system read and write an agent performs.
  • Conversation transcripts retained under your retention policy, exportable on demand.
  • PII masking on logs and transcripts, configurable per deployment.

Data handling

  • Your proprietary data never trains shared public models.
  • In-Kingdom hosting with full data residency, available from day one.
  • Reference architecture aligned to NCA CCC-2; MSA, DPA, and SOW ready for procurement.

Where the data sits

A dedicated VPC deployment. Nothing crosses the boundary except the customer conversation itself.

Your VPC — inside national borders

  1. Channel edge

    Web widget, WhatsApp, voice, video, email, API

  2. Hyper Human runtime

    Orchestration, memory, policy, escalation

  3. Private knowledge index

    Your docs, decks, FAQs — encrypted, tenant-private

  4. Connector layer

    Scoped, audited read/write into your systems

  5. Your systems of record

    CRM, ERP, commerce, helpdesk, warehouse

No data egress outside the boundary

Shared-cloud deployments run the same components in a multi-tenant KSA region; self-hosted runs the identical stack inside your own data centre.
>99%
target uptime
<1.2s
target response latency
100+
target parallel sessions

Target SLAs — pre-launch reference architecture.

Discuss your architecture