A privacy gateway for AI.

Use any AI model. Keep your customers' identities in the Kingdom.

DataSitr checks each request for personal data, applies tenant policy, and routes the resulting payload to a configured provider—or blocks the request.

Synthetic example Policy checked
What your team typed Summarize the order for Aisha Al‑Otaibi, phone +966 50 000 0000.
What the model receives Summarize the order for [[PERSON:01]], phone [[PHONE:01]].
PERSON · PHONE Green route eligible
Reads Arabic and English

Arabic names, Saudi number formats, and the usual identifiers in both languages.

Decides Three plain outcomes

Send with placeholders, keep in the Kingdom, or block. You can read the rule for each.

Keeps A record of every decision

Dated, hash-chained, and readable by your DPO or a reviewer.

Shows its work 181 controls, published

Each tied to a test or a dated piece of evidence. Benchmark and trust report, no sign-in.

How it works

One request. One policy decision.

The request is checked before a provider route is selected.

01

Detect

Identify direct identifiers and selected combination risks in Arabic and English text.

02

Minimize

Replace direct identifiers with typed placeholders when policy allows.

03

Route

Route the permitted payload to a configured external provider, use a configured in-Kingdom path, or block the request.

In A request from your team or system

Exactly as written, in Arabic or English.

DataSitr Detect, minimize, decide

Original values go to an encrypted vault in the Kingdom and come back into the answer on the way out.

Green

Tokenized before eligible external processing.

Amber

Pseudonymized, then routed to a configured in-Kingdom path.

Red / block

Raw sensitive content goes only to a configured in-Kingdom path; otherwise the request is blocked.

Tokenization reduces direct-identifier exposure. It does not remove every contextual or legal transfer risk.

What it finds

The identifiers that actually show up in Saudi work.

A model fine-tuned for Arabic, plus pattern recognizers for Saudi formats. Not a generic English filter with Arabic bolted on.

National ID Iqama number Passport number IBAN Saudi phone numbers Names, Arabic and English Addresses Commercial registration Email addresses Card numbers Dates and birthdays Medical record numbers Combinations that identify someone

Production detection threshold: 0.7 confidence. Amber marks combination risks, which are flagged rather than replaced. Measured results are on the benchmark page.

Who this is for

Teams whose customer data is already reaching an AI.

Usually through a chat window, a summary tool, or a vendor's feature. The gateway puts a policy in front of it. The assessment tells you where you stand first.

Hajj and Umrah operators

Pilgrim files pass through many hands.

Passports, health forms, and visa details for whole groups. Ask an AI to summarize a group file and the identifiers ride along.

Which third parties receive them, and what leaves the Kingdom?

Clinics and hospital groups

Patient notes are written in Arabic.

Medical record numbers, dates of birth, and diagnoses in free text. A transcription or summary request should not carry them out of the Kingdom.

Can you show what the model actually received?

Insurers and finance

IBANs and IDs hide in support tickets.

Claims histories, underwriting notes, and customer messages get pasted into AI tools because it is faster. The gateway keeps the fast part and removes the identifiers.

Who gets called at hour zero of a breach, and is the 72-hour path written down?

Retail, apps, and marketing

Customer lists and consent, side by side.

SMS campaigns, loyalty data, and support chat. The records the gateway keeps are the ones a reviewer asks to see.

Can you show consent for each message you sent?

Start here

Start with a 10-business-day readiness assessment.

If a PDPL notice arrived tomorrow, could your team produce the evidence within five days? The assessment answers that on paper, with fixed scope, documents and synthetic material only, and four deliverables your team can act on.

10 business days Two starts per month No production data
01 Findings register

Risk-ranked, with evidence references and named control owners.

02 Control map

Mapped to PDPL requirements with implemented, partial, missing, and evidence-gap states.

03 Remediation plan

Ordered by risk, dependency, and practical sequence.

04 Executive readout

Material exposure, immediate decisions, and the next evidence gates.

Straight answers

The questions people ask first.

Do you see our data?

For the assessment, no. It uses documents plus synthetic or redacted material, with no access to your systems and no production personal data. For the gateway, original values stay in an encrypted vault hosted in the Kingdom; an external model receives the placeholder version, and only when your policy allows it.

Which AI models can we use?

Any provider configured for your tenant. The pilot has routes for OpenAI, Anthropic, Google, Groq, and STC SambaNova, and in-Kingdom paths are configured per tenant. The full provider list is on the sub-processors page.

Is DataSitr approved by a regulator?

No. DataSitr is registered on the National Data Governance Platform as a data services provider, which means registered, not licensed. The status of our accreditation application is written up with dates on the Trust page, and we will not describe it as anything more than it is.

How big is DataSitr?

One founder-operator in Jeddah, who is the registered DPO. The gateway runs as a live pilot, not a proven high-availability platform. We say this plainly because you would find out anyway, and because the evidence pages are built to survive that question.

What does the assessment cost, and how long does it take?

A fixed fee in two milestones, ten business days from accepted intake, and at most two starts a month. The exact figures and payment terms are on the assessment page, so that nothing here is a surprise on the call.

What happens after I write to you?

You hear back from the operator, not a sales team. We hold a 20-minute call to check fit and pick a start date, then you receive a written scope. No documents are needed for the call.

Where we are

Small, honest, and in the Kingdom.

The gateway runs as a live pilot. Continuity has been drilled on dated occasions; it is not a standing availability guarantee.

Every control we claim is tied to a test or a dated piece of evidence, and the trust report lists what it does not prove.

The assessment is a technical and operational review. Regulatory standing, in writing, is on the Trust page.

Evaluation

Evaluate it on one defined workflow.

Start with a scoped pilot and an agreed evidence plan.