Your data stays
where you need it. Always.
Eshal is built for industries where data residency, compliance, and auditability are non-negotiable. Every deployment option, certification, and control is documented here - no vague claims.
Citizen, patient, and customer data never leaves the country. Ever.
Every Eshal deployment is pinned to a specific geographic region. Data is processed, stored, and backed up exclusively within that region. No cross-border transfer occurs without explicit written consent.
UAE - Primary Region
All UAE deployments run on OVHcloud Dubai. Data processed, stored, and backed up exclusively within the UAE. Meets CBUAE, DHA, MOH, TDRA, and UAE PDPL residency requirements.
In-country sovereignty certificate · OVHcloud Dubai · Primary region for all UAE deploymentsKSA - Saudi Arabia
Saudi deployments run on infrastructure within the Kingdom. Meets SDAIA PDPL and SAMA data localisation requirements for regulated deployments.
Saudi data residency for KSA-regulated deploymentsEU - European Region
GDPR-compliant European residency for deployments serving EU data subjects. Standard Contractual Clauses provided. Data never transits outside the EEA.
GDPR-compliant EU residency for European deploymentsThree ways to run Eshal.
One level of security.
Choose the deployment model that matches your organisation's compliance posture and IT infrastructure - from managed cloud to fully air-gapped on-premise.
Managed Cloud
Fully managed SaaS deployment on Eshal's UAE-hosted infrastructure. Fastest time to go live - typically one day.
- ✓ UAE data residency (OVHcloud Dubai)
- ✓ ISO 27001 infrastructure
- ✓ 99.9% uptime SLA
- ✓ Automatic security updates
- ✓ Multi-tenant with strict isolation
- ✓ Data residency certificate on request
Private Cloud
A dedicated Eshal instance inside your own cloud account (UAE AWS, Azure UAE, or your OVHcloud tenancy). Your infrastructure, our software.
- ✓ Isolated instance - no shared compute
- ✓ Your cloud account, your keys
- ✓ BYOK (Bring Your Own Key) encryption
- ✓ Custom data retention policies
- ✓ VPC peering to your existing systems
- ✓ Dedicated IP and network controls
On-Premise / Air-Gapped
Full Eshal platform deployed inside your own data centre. No data leaves your walls. Managed via Eshal's Distributor console.
- ✓ Runs entirely within your infrastructure
- ✓ Air-gapped deployment available
- ✓ Distributor console for multi-tenant ops
- ✓ Self-hosted LLM models supported
- ✓ No internet connectivity required
- ✓ Full source access on enterprise plans
How data flows - and where it stops.
A complete picture of how customer data moves through the Eshal platform, what stays in your region, and what never leaves your control.
Every organisation gets a sandboxed workspace - its own agents, knowledge base, inbox, and data. No cross-tenant data access is architecturally possible.
Each tenant's data is encrypted with a unique key. Private Cloud and On-Premise deployments support BYOK - you hold the master key, we cannot access your data.
Granular roles: Platform Admin, Agent Builder, Viewer. Every permission is scoped to your org only. Access logs available in real time.
Every certification your procurement
team will ask for.
Eshal meets the compliance requirements for regulated industries across the UAE, GCC, and global markets.
ISO 27001:2022
Information security management system. Covers access control, incident response, risk management, encryption, and change management. Audited annually by an accredited third party.
Scope: Full platform · Certificate available on requestUAE Federal Data Protection Law (PDPL)
Federal Decree-Law No. 45 of 2021. Covers consent, data subject rights, processor obligations, and cross-border transfer restrictions. All UAE deployments comply by default.
Scope: All UAE-deployed workspaces · DPA availableDIFC Data Protection Law 2020
DIFC DPL 2020 and associated regulations. Covers data processing, international transfers, and subject access rights for DIFC-registered entities and their processors.
Scope: DIFC deployments · Processor agreement availableTDRA Digital Service Standards
UAE Telecommunications and Digital Government Regulatory Authority standards for digital government services. Required for public sector and smart government deployments.
Scope: Government deployments · Assessment report availableGDPR (EU General Data Protection Regulation)
Full GDPR compliance for EU and EEA data subjects. Covers lawful basis, data minimisation, subject rights, DPO engagement, and cross-border transfers via Standard Contractual Clauses.
Scope: EU-resident data subjects · SCCs and DPA availableHIPAA-Aware Architecture
Built with PHI and PII handling controls consistent with HIPAA requirements. Encryption, access controls, audit logging, and BAA availability for US-compliant healthcare deployments.
Scope: Healthcare deployments · BAA available for enterprisePCI DSS Awareness
Payment handling workflows are architected to avoid direct PCI scope. Card data is never stored or processed by Eshal - payment links route to compliant payment processors.
Scope: Payment-adjacent workflowsCBUAE & DFSA Guidelines
Aligned with Central Bank of UAE and Dubai Financial Services Authority technology risk and outsourcing guidelines for financial service deployments in UAE and DIFC.
Scope: Banking & finance deploymentsSOC 2 Type II
Security, availability, and confidentiality trust service criteria. Audit in progress - report expected H2 2026. Bridge letter available for enterprise procurement requirements.
Scope: Full platform · Bridge letter available nowCompliance built for your sector.
Every regulated industry has additional compliance requirements. Eshal is pre-configured for each.
Banking & Finance
Central bank and financial regulator requirements across MENA
Healthcare
Health authority data handling and patient privacy standards
Government
UAE public sector digital and data governance frameworks
Telecom
Telecom regulator subscriber data requirements
The technical details your
security team needs.
Exact specifications for every encryption layer, key management approach, and security control. No vague claims.
Encryption specifications
Access & authentication controls
Every action. Every actor. Every second.
Every interaction with Eshal - customer conversations, agent actions, platform changes, API calls, escalations - is logged in an immutable, searchable audit trail. Regulatory-grade records for compliance, investigations, and FOI requests.