Sovereign AI · On-premise · للمملكة

Governance, risk & compliance, in the clear.

The AI-first GRC platform for the Kingdom's most regulated organizations — every risk, control and obligation in one clear view, with intelligence that runs entirely inside your own walls.

NCA · SAMA · PDPL pre-loaded 100% on-premise AI Arabic & English, RTL-first
Bank Al-Waseet

Recorded in the platform. Demonstration data — not a real organisation.

Aligned to the frameworks that govern the Kingdom
NCA ECCNCA CCCSAMA CSFPDPLISO 27001ISO 22301NIST CSFNCA ECCNCA CCCSAMA CSFPDPLISO 27001ISO 22301NIST CSF
From spreadsheets to one record

The work already exists. It is just scattered across eight places.

Nobody fails an audit because they did not care. They fail because the evidence existed and could not be found in time. Wathiq connects the same material into one record you can follow.

controls_Q3_FINAL_v7.xlsxRE: RE: evidence A.5.26?SAMA_gap_analysis(2).xlsxaudit_findings_draft.pdfregister_copy_of_copy.xlsxscreenshot_2026-08-11.pngevidence_final.zipwho owns this control?RegulationRequirementControlRiskEvidenceFindingRemediationAssuranceToday: eight places, no relationshipsWathiq: one record, every connection
A different category

Not another GRC tool — a sovereign one.

Legacy compliance software was built elsewhere, for elsewhere, and runs on someone else's cloud. Wathiq was built in the Kingdom, for the Kingdom — sovereign by design, not by configuration.

Legacy & foreign GRC
Where your data lives
A foreign public cloud
The AI
A black box, processed offshore
Frameworks
Western controls, retrofitted
Architecture
Disconnected, siloed modules
Language
English-first, Arabic bolted on
Deployment
Vendor's cloud, take it or leave it
Wathiq
Where your data lives
Your own infrastructure — 100% on-premise
The AI
Runs on your hardware, fully explainable
Frameworks
NCA · SAMA · PDPL, native from day one
Architecture
One connected golden thread
Language
Arabic-first, genuinely bilingual & RTL
Deployment
On-premise or your private cloud — your call
One connected platform

Every risk, control, policy and vendor — woven into one golden thread.

Wathiq links the entire GRC lifecycle so nothing lives in isolation. A control maps to a framework, carries its evidence, drives a risk, raises a finding, and rolls up to the board — automatically.

Governance & Policy

Policy lifecycle with versioning, committees, workflows and multi-stage approvals — mapped to the controls they satisfy.

VersioningApprovalsCommittees

Risk Management

A living register with 3×3–5×5 methodologies, FAIR-style monetary quantification, KRIs, scenarios and emerging-risk countdowns.

FAIR / ALEKRIsScenarios

Compliance & Audit

Pre-loaded NCA, SAMA, PDPL, ISO & NIST libraries with AI cross-mapping, maturity assessments and a full audit lifecycle.

NCA ECCSAMA CSFPDPL

Third-Party Risk

Auto-tier vendors 1–4, dispatch tier-matched questionnaires, and collect answers through an isolated supplier portal.

TieringSupplier portal
Open the supplier portal →

Incident Command

A unified incident hub with the PDPL 72-hour breach clock, cross-module lineage and AI-drafted narratives.

PDPL 72hBreach lineage

Human Risk

Awareness, phishing simulation and a behavioural human-risk index that posts training completions as live evidence.

AwarenessHuman Risk Index
Sovereign AI

Intelligence that never leaves your walls.

Wathiq runs its AI on a model hosted inside your own infrastructure — CPU or GPU, on-premise or your private cloud. No prompt, no document, no regulated record is ever sent to an external API.

NLP control mapping across 500+ regulatory controls.
Explainable risk scoring — every score carries SHAP reasoning.
Evidence classification — auto-matched to the controls it proves.
Bilingual report generation — board-ready Arabic & English.
Cross-framework mapping — assess a control once, carry it to the others, with human confirmation.
AI Runtime · Local
Model locationOn-premise
External API calls0
Data egressNone
LanguagesAR · EN
ExplainabilitySHAP
DeploymentCPU / GPU
14
KSA & international frameworks pre-loaded — NCA, SAMA, PDPL, ISO, NIST
100%
On-premise AI — zero external data egress
72h
PDPL breach-notification clock, tracked automatically
2
Languages, RTL-first — Arabic & English throughout
Enterprise security & isolation

Built for ministries, banks and critical infrastructure.

Strict multi-tenant isolation enforced at the database with row-level security, a tamper-evident audit trail, and phishing-resistant authentication — the assurances a regulated enterprise requires.

Tenant isolation — row-level security on every table; no cross-tenant leakage, by design.
Tamper-evident audit — a hash-chained, independently verifiable trail of every action.
AD / SSO & MFA — directory sign-in, TOTP, email OTP and WebAuthn passkeys.
Data protection — field-level encryption, DLP watermarking and IP allow-listing.
On your terms

On-premise, or your private cloud.

Single-command Docker inside your data centre — air-gap capable — or a containerized deployment to your own cloud. The platform and its AI always stay under your control, resident in the Kingdom.

GovernmentSemi-governmentBanking · SAMAHealthcareTelecomOil & GasEnergy & UtilitiesManufacturingConstructionUniversitiesLarge enterprises

See your governance, risk and compliance in the clear.

Request a private demonstration and we'll walk your team through Wathiq on your frameworks, in your language, on your infrastructure.