April 21 ACK baseline The current live ACK/API baseline was re-proved on April 21.

The guarded rollout re-proved authenticated health, metrics, compliance-route checks, public readiness, 2/2 Ready pods, per-pod health, and alert delivery. This remains dated runtime evidence, not a blanket HA promise.

Control traceability 126 controls are tracked, with 102 code-test, 13 dated-evidence, 10 external-fact, and 1 pending substantiation classifications.

The public trust report was generated from the matrix on 2026-04-21T07:05:50Z and intentionally excludes file paths, line numbers, and reviewer-only mappings.

KMS + detector evidence Alibaba KMS startup bootstrap remains live, and the public benchmark artifacts carry the April detector evidence.

Keep key-custody claims bounded to startup bootstrap on the serving ACK image; tenant BYOK and HSM custody remain outside the current live boundary.

Boundary “Proven” means measured or drilled on the live pilot.

If a capability has not been exercised on the live pilot or cannot be reproduced from retained evidence, it stays outside the proof language.

Verification Public artifacts are sanitized; full mappings are request-gated.

Use the public trust report, control-matrix summary, and benchmark JSON for buyer-safe review. Qualified reviewers can request the signed bundle for control-level implementation, test, and evidence mappings.

Not implied Trust evidence is not the same thing as a blanket availability or immutable-retention claim.

Where the evidence is narrower, the wording stays narrower: broader availability, automatic failover, full-vault verification, and final immutable-retention controls remain explicit separate steps.

02

What is proven now


The current top-level proof boundary is the April 21, 2026 live ACK/API baseline plus sanitized public artifacts generated from the current control matrix. Older continuity drills remain retained evidence, but they are no longer the headline posture; the retained set includes April 6, 2026 planned maintenance continuity evidence.

Treat April 21 runtime evidence as dated proof of the checked surfaces, not as a broad HA, external audit, regulator approval, or HSM-custody claim.

Capability
Evidence
April 21 live ACK baseline

The April 21 guarded rollout re-proved authenticated health, metrics, compliance-route checks, public readiness, 2/2 Ready pods, per-pod health, recovery freshness, deploy-host alert self-test, and in-workload alert delivery. The full same-origin browser/OIDC pack remains last refreshed on April 18, so broader browser/auth parity stays outside this page's current proof language.

Control matrix and public trust report

The current public trust report summarizes 126 controls: 102 substantiated by code tests, 13 by dated live evidence, 10 by external facts, and 1 unspecified-pending control. The JSON totals are generated from docs/generated/control_matrix.json and intentionally exclude file:line references and reviewer-only mappings.

PDPL citation integrity

The authoritative SDAIA-published PDPL English text is the in-repo citation source of truth. The citation validator supports automated review of article references across code and docs; this is citation-integrity evidence, not an external legal opinion.

Detector benchmark artifacts

The public detector artifacts were refreshed in April with sanitized provenance. The latest public precision/recall artifact passes its curated benchmark snapshot, and the public PII benchmark reports a 31.48 ms p95 for the 1K-character English case. Treat those as dated curated-corpus benchmarks, not production-wide coverage or an external audit.

Billing integrity

Billing events are written with SHA-256 hash-chain continuity and HMAC authentication for newer records. A 10-year retention gate refuses in-retention deletion and produces a companion compliance record.

PII detection

English, Arabic, and Saudi-specific patterns (National ID, IBAN, phone). Measured detector results are published on the benchmark page and refreshed from the current public benchmark summary instead of being frozen here.

Three-lane privacy routing

Green (anonymized external), Amber (pseudonymized in-Kingdom), Red (raw in-Kingdom). Lane enforcement is policy-driven and tenant-configurable.

Encrypted vault

AES-256-GCM at rest with per-tenant derived keys. TLS 1.2/1.3 in transit.

Guarded deploy with rollback

A forced public-smoke failure triggered automatic rollback, restoring the exact deploy hash and health. The rollback proof note is archived in the repository, and raw drill logs are retained separately.

Signed evidence export

Sequenced processing records can be exported with signed verification material for buyer or regulator review. Final immutable-retention posture remains a separate operational step.

Off-host encrypted backup

Dated pilot evidence notes cover encrypted upload, download, and restore-drill verification on the pilot host. Treat freshness as an operator-verified date, not a standing guarantee from this page.

Isolated restore recovery

A March 28, 2026 drill restored an encrypted backup into an isolated environment and completed fresh logins successfully. This proves single-stack recoverability, not public cutover or zero-downtime DR.

Monitoring and alerting

The pilot has active health monitoring, metrics collection, log retention, and alert delivery. Freshness is treated as dated operator evidence, not a permanent guarantee from this page.

Shared-state scaling evidence

The live pilot has dated scaling evidence beyond a single-process setup, but the public claim remains narrower than hitless deploys or broader HA.

Auth survivability

A March 29, 2026 drill showed that fresh login and authenticated processing survived an intentional auth-path outage on the public service. This is continuity evidence, not blanket HA.

Public restored-state cutover

A March 29, 2026 drill completed a public restored-state cutover from a dated encrypted backup. The latest rerun also verified that the oldest and newest restored vault rows decrypt successfully under the restored environment. This remains a narrow restored-vault read-back check, does not prove that every vault row decrypts, and does not imply full-vault verification, automatic failover, or blanket HA.

Alternate public path

A separate March 29, 2026 drill showed that the public path could be served through an alternate host under operator control. This is continuity evidence, not replication, automatic failover, or blanket HA.

03

Registrations & regulatory status


Each item below is the exact phrasing the issuing authority has put in writing. We deliberately distinguish "registered" from "licensed" and "application in progress" from "awarded" — because the Saudi regulators do.

Registration
Status
National PDP Register #3260005651

Active. The owner is the registered Data Protection Officer for مؤسسة داتا ستر / Data Sitr Establishment under the Saudi Personal Data Protection Law (PDPL).

NDGP Data Services Provider Registration LR-25-000018

Registered as a data services and products provider on the National Data Governance Platform (NDGP); status "Complete" on the dashboard. NDMO has clarified in writing (2026-04-27) that this registration does NOT constitute a license — the licensing application window will open in an upcoming phase.

SDAIA AI Service Provider Accreditation AE-26-000237

Application In Progress with the Saudi Data and AI Authority (filed 2026-04-03). The accreditation has not been awarded; we will update this row when SDAIA issues the decision.

Commercial Registration 7030618388

Active under the Ministry of Commerce since 2022-08-31. Entity type: Establishment. Registered under the current name مؤسسة داتا ستر / Data Sitr Establishment.

Standing inquiries are open with NDMO, SDAIA, NCA, DGA, and the Etimad procurement center on AI Adoption Framework applicability and AI/ML tender evidence requirements; substantive answers will be reflected here as they arrive.

04

What buyers can inspect today


These are the assurance surfaces a buyer or security team can inspect immediately without widening the claims boundary.

Control Traceability Matrix 126 controls are mapped into substantiation classes that buyers can inspect safely.

The public trust report shows the aggregate proof counts, while the full Ed25519-signed reviewer bundle remains available to qualified reviewers on request.

Public Trust Report A sanitized report now summarizes what the matrix proves without leaking file paths or line numbers.

Open the report at /trust-report or consume /resources/trust-report.json for automated review; the totals match the generated control-matrix JSON.

PDPL Citation Integrity The authoritative SDAIA-published PDPL English text is included in-repo as the citation source of truth.

A per-citation validator at scripts/validate_pdpl_citations.py enables automated audit of article references across the codebase.

Live Key Custody The April 21 live baseline continues to bootstrap its startup master key through Alibaba KMS.

Keep that claim bounded to startup bootstrap on the serving ACK image. Tenant BYOK and HSM custody remain outside the current live boundary.

  • Public reviewer artifactspublic trust report, control matrix summary, compliance reviewer pack, benchmark JSON artifacts, and the compliance summary page
  • Dashboard compliance tabprocessing records, DPIA, audit summary, evidence pack, and compliance bundle with copy/download for procurement review
  • Dedicated regulator portalread-only regulator access during evaluation by request, with cross-tenant processing records, SDAIA-shaped report builders, scoped signed-package generation for handoff artifacts, and a separate regulator access log
05

What is not yet claimed


DataSitr is intentionally specific about what it has not yet proven. The current non-claims list now lives on the compliance page so procurement and diligence teams can review the same boundary in one place.

06

Test coverage snapshot


Surface
Current result
Backend tests

See current dated snapshot

Dashboard unit/integration

See current dated snapshot

Dashboard production build

Passing

The current verified snapshot is kept as a dated internal evidence note rather than repeated here as a hard-coded count. The covered surfaces still include PII detection, tokenization, vault encryption, pipeline orchestration, admin authorization, webhook delivery, monitor health, deploy/backup/restore scripts, and dashboard UI.

07

How to verify


Buyers evaluating DataSitr should:

  • Request a pilot API key and test detection and routing with their own representative data
  • Open the public trust report and compare /resources/trust-report.json totals against /resources/control_matrix.json
  • Review the compliance bundle in the dashboard (copy or download as JSON for internal review), or download branded evaluation PDFs from the resources page
  • Check the evidence pack sections for integrity, external evidence, and policy snapshot status
  • Request regulator-portal access when the evaluation requires cross-tenant evidence, SDAIA-shaped report builders, or scoped signed-package generation
  • Verify scoped signed packages using the published verification details rather than relying on screenshots or forwarded files alone
  • Ask about any item in the 'not yet claimed' section — questions go to dpo@datasitr.com

See it work on your data.

Evaluate →