Sovereignty & compliance
Your archive never leaves your country.
GCC banking regulators require customer data to stay in-country and expect banks to seek approval before outsourcing. EVaultOne is built around that: a separate platform in each country, two sites per country, and a ready-made pack to support your regulator submission.
Where we host
| Country | Status | Note |
|---|---|---|
| United Arab Emirates | Launching first | Two separate in-country data centres |
| Qatar | Next | — |
| Saudi Arabia | Planned | — |
| Bahrain | Served from the UAE | Subject to customer's regulator approval |
| Kuwait | Planned | — |
| Oman | Planned | — |
Regulators and frameworks we map to
- CBUAE (Outsourcing Regulation for Banks)
- Dubai Electronic Security Center (DESC)
- Qatar Central Bank (QCB cloud regulation)
- Saudi Central Bank (SAMA)
- National Cybersecurity Authority (NCA)
- Central Bank of Bahrain (CBB)
- UAE Personal Data Protection Law
We provide the evidence and documentation your compliance team needs. Regulatory approval remains your organisation's decision.
Security controls
- Encrypted in transit and at rest
- Access only by named, vetted engineers, with full audit logging
- ISO 27001 certification in progress
- Immutable backups and regularly tested restores
Regulator approval support pack
- Architecture description
- Data-flow and data-location statement
- Security controls matrix
- Business continuity and exit plan
- Audit rights clause
- Sub-processor list