Credentials
National Cybersecurity Authority licence
- Licence: Managed Security Operations Center (MSOC) Services Licence — Tier 2.
- Licence number: 010220341.
- Validity: 2026-07-14 to 2031-07-14.
- Scope: a Tier 2 licence authorises the provision of managed SOC services to any organisation other than government entities and organisations that own, operate or host critical national infrastructure.
- Verification: you can confirm our listing in the registration and licensing registry on the NCA website, nca.gov.sa (registration and licensing page, managed SOC service providers category).
Official records
- Legal name: Data Security for Cyber Security.
- Commercial registration: 1010752666.
- Unified establishment number: 7026307020.
- Group: EXA Information Technology.
Managed Security Operations Center (MSOC) Services Licence — Tier 2
Licence number: 010220341
How this website protects your data
This website is fully separate from our SOC systems and holds no operational client data. The only data it processes is what you submit through the service-request, careers and data-request forms.
- Hosting location: the website runs on a DataSec-operated server in a LeaseWeb data centre in the Netherlands, which also holds private files, and the database is with Neon in Frankfurt, Germany, under a documented transfer assessment and contractual safeguards. We re-evaluate in-Kingdom hosting as suitable options become available.
- Encryption: every connection to the site is encrypted with HTTPS, and the database is encrypted at rest.
- File storage: CVs and RFP files are stored in private storage that cannot be reached by a public link and are deleted when the retention period ends.
- IP addresses: we do not store your IP address in its original form; we keep a salted hash used only for abuse prevention.
- Audit log: every view, export or deletion performed by our staff on your requests or data is recorded in an append-only audit log.
- Internal access: staff accounts are protected with two-step verification, and access is granted by role.
- Abuse protection: network protection through Cloudflare, and rate limits on forms and API routes.
- Analytics: we use no analytics or visitor-tracking tools and no advertising modules.
Retention periods
- Service and consultation requests not converted to a contract: 24 months.
- Job applications: 12 months from the last activity.
- Talent network (separate consent): 24 months.
- Data-subject requests: kept as evidence of completion for the period the law requires.
Personal data protection
We process your personal data under the Personal Data Protection Law (PDPL) and its Implementing Regulations issued by the Saudi Data and AI Authority (SDAIA).
Purposes
- Responding to service and consultation requests and communicating about them.
- Assessing job applications and communicating with candidates.
- Operating the website and protecting it from abuse.
- Fulfilling data-subject requests and evidencing completion.
Your rights
- Access your data and obtain a copy of it.
- Correct inaccurate or incomplete data.
- Request deletion when the purpose no longer applies.
- Withdraw consent at any time without affecting earlier processing.
- Object to processing in the cases the law allows.
We respond to verified requests within 30 days of receipt, as the Implementing Regulations require. To submit a request, use the "Request about my data" form on the privacy policy page or write to info@datasec.sa. You also have the right to lodge a complaint with SDAIA.
Full details are in the privacy policy and the candidate privacy notice.
Security of the SOC operation
The managed SOC is operated from Riyadh under the requirements of the NCA licensing framework for managed SOC providers. The following is a general description; we do not publish operational details or beneficiary data.
- Segregation: the SOC environment is isolated from the office network and from this website, and neither connects to client systems except through contractually agreed channels.
- Access: analysts receive role-based, least-privilege access with multi-factor authentication and access logs that are reviewed regularly.
- People: SOC staff undergo pre-employment screening and sign written confidentiality obligations.
- Data: monitoring data is handled under the regulatory framework's requirements, including in-Kingdom location requirements, and no data about beneficiaries or their incidents is published without written approval from the NCA and the client.
- Continuity: documented continuity and recovery plans that are tested regularly.
Architecture and control details are provided to qualified clients in the due-diligence pack under a non-disclosure agreement.
Vendor due-diligence pack
If you are assessing us as a vendor, we provide a standard pack that answers most questions in bank and regulated-entity security questionnaires. The pack includes:
- A copy of the NCA licence.
- A summary of our information security, business continuity and incident management policies.
- A general description of the SOC architecture and environment segregation.
- The list of sub-processors and processing locations.
- A template data-processing agreement and confidentiality terms.
The pack is sent after a short qualification to confirm that the requester is a prospective client or an auditor acting on its behalf, and it is provided under a non-disclosure agreement. Use the short form below and our account team will contact you to complete qualification.
Request the due-diligence pack
Responsible disclosure
If you discover a security vulnerability in a datasec.sa web property, we welcome a report at info@datasec.sa. Scope, safe harbour for good-faith research and what to include in a report are set out in the responsible disclosure policy. A security.txt file is also available at /.well-known/security.txt.
Contact
Let's talk about what you need
We answer enquiries through the form, WhatsApp, a call or email.
Mobile (calls and WhatsApp)
+966 59 750 4669Email
info@datasec.sa

