Enterprise teams get SSO, tenant isolation, and a separate regulator portal. Current continuity proof covers five dated continuity drills and the May 4 ACK customer route; every boundary is explicit.
SSO, three operator roles, scoped keys, and a read-only regulator portal.
tenant, tenant_admin, super_admin for operator surfaces; the regulator portal is a separate path with its own audit log for regulator sessions.sv_ prefix and a role scope. Revocation is effective immediately; cached state is invalidated across replicas via Redis.Five layers — keys, access, logs, policy, rate — enforced independently. A misconfiguration on one layer does not fall back to a shared default.
Designed to support PDPL alignment. SOC 2 Type II + ISO 27001 audits planned, not yet certified.
Designed to support PDPL alignment; not a legal determination
Controls implemented; independent audit not yet completed
Controls implemented; certification work not yet completed
Important: DataSitr is designed to help organizations align with PDPL. It does not itself grant compliance.
Raw personal data stays in Saudi by default; only tokenized green-route text can leave the Kingdom.
force_in_kingdom — when set, the router rejects any request that cannot be served by an operator-configured in-Kingdom path. The block is explicit and audit-logged — there is no silent fallback.Tenant, operator, and regulator users each get a separate path. The regulator portal has its own audit log.
/v1/chat/completions; DataSitr applies detection, lane decision, audit records, and provider policy. Tenant dashboard exposes DPIA, audit summary, evidence pack, and the one-click compliance bundle.
Multi-AZ ACK ingress with verified cutover + 4-hour soak; failover drills planned. Five dated continuity drills remain behind the operational posture. No contractual SLA yet.
Pilot support runs through a direct operator channel while a formal support policy is finalized. As of 2026-05-04, multi-AZ ACK ingress has verified cutover + 4-hour soak evidence; failover drills are planned. Full-vault verification, HSM custody, and unplanned full-region failure tolerance remain separate steps.
Pilot → Growth → Enterprise. Same components; replicas + state stores scale up, runtime topology stays identical.
Next investments on the enterprise track — explicit and dated. None of these block a pilot today.