Trust
Trust and security
What this company is, how it handles information, and which security controls exist today. Every line below is marked with whether it is in place, scoped per deployment, or absent.
What this page is not
Alsadaany Industries holds no security certification, has completed no third-party audit, and operates no customer deployment. Nothing on this page should be read as a compliance attestation. It is a statement of position, published so a reviewer can see the gaps without having to find them.
Identity
Who you would be contracting with
Where a specific registration number or registered address is required for procurement, request it directly rather than relying on this page.
- Legal name
- Alsadaany Industries
- Jurisdiction
- Arab Republic of Egypt
- Delivery
- International
- Founded and led by
- Omar Alsadaany, Founder
General enquiries: contact@alsadaany.com
Controls
Deployment and data residency
Where a deployment runs decides most of the rest. The default is inside your boundary, which is the answer that matters for operational data.
Self-hosted deployment
Status: Per deploymentThe engine runs on your infrastructure. The model, the runs and the operational data stay inside your boundary.
Fully local execution
Status: ImplementedA local edition of the platform runs entirely on one machine with no checkout, no licensing call and no outbound network request. This is the strongest available answer for data that may not leave a site.
Private cloud deployment
Status: Per deploymentDeployment into your own cloud tenancy, against your networking and access requirements, agreed during Discovery.
Multi-tenant hosted service
Status: Not in placeThere is no shared hosted offering. Every deployment is single-tenant, and a multi-tenant service is a direction rather than a product.
Data residency guarantees
Status: Per deploymentFollows from where the deployment runs. Because deployment is inside your boundary, residency is a property of your infrastructure rather than a commitment we make on your behalf.
Controls
Access and authorisation
What the platform implements today, and what an enterprise deployment would have to add.
Authentication
Status: ImplementedThe platform authenticates accounts and scopes projects and files to the account that owns them.
Role-based access control
Status: Not in placeAccounts and ownership exist. Roles, per-project permissions and delegated administration do not. An enterprise deployment would scope them against your identity provider, and that is engineering work rather than configuration.
Single sign-on
Status: Not in placeNo SAML or OIDC integration exists today. It would be built per deployment against your provider.
Audit trail
Status: Not in placeJob history is recorded, but there is no access audit log suitable for a compliance review. This is a known gap and is named here rather than left for a reviewer to discover.
Controls
Data handling
What happens to information that reaches this company.
Project and file isolation
Status: ImplementedProjects and input files are owned by an account and scoped to it in the schema. This is the platform's own model and is not a substitute for a security review of a specific deployment.
Input integrity
Status: ImplementedInputs are hashed on upload and a job records what it ran against, so a result can be traced back to the exact inputs that produced it.
Encryption in transit
Status: ImplementedPublic properties are served over HTTPS with HSTS. Platform APIs are served over TLS in any deployment reachable across a network.
Encryption at rest
Status: Per deploymentA property of the storage the deployment runs on. Because deployment is inside your boundary, it is configured with your infrastructure rather than promised independently of it.
Backups and retention
Status: Per deploymentScoped with the deployment. There is no default retention schedule we would apply to your data without agreeing it first.
Website data collection
Status: ImplementedThis website runs no analytics, no tracking scripts and no advertising pixels. Enquiry details are used only to answer the enquiry, and are not sold, shared or used for advertising.
Controls
Engineering practice
The controls that sit in how the software is built.
Version control and review
Status: ImplementedSimulation code is reviewed and version-controlled to the same standard as production software.
Automated testing
Status: ImplementedTest suites are written against engine behaviour rather than against interfaces. The mission twin's engine carries 198 tests.
Reproducible builds and runs
Status: ImplementedContainerised environments, seeded runs and versioned inputs, so a reported figure can be regenerated exactly months later.
Secrets handling
Status: ImplementedCredentials are read server-side only and are never included in a browser bundle. No credential is committed to a repository.
Independent penetration testing
Status: Not in placeNo third-party penetration test has been carried out. When one has, this line will say so and name the date.
SOC 2, ISO 27001 or equivalent
Status: Not in placeNo certification is held and none is in progress. Any supplier questionnaire that requires one will not be satisfied by this company today.
Legal
Published terms
Next step
Security review before scope
If your organisation runs a supplier assessment, send it early. The answers above are the ones we would give, and it is better to find a blocker before a scoping conversation than after one.
Prefer email? sales@alsadaany.com