Regulatory Compliance
Cybersecurity and Compliance
Last updated: 23 August 2026
Data Sovereignty & Site Flow
We apply the principle of minimizing the attack surface and data protection responsibility from the ground up; our site does not retain unnecessary intermediary data, and all systems we build are subject to national cybersecurity controls.
-
01
Direct, limited input The enquiry and career forms only. No tracking cookies, no advertising networks.
-
02
Encrypted transit Hosting is managed via Vercel; form delivery via Resend. Both ensure end-to-end encryption during transit.
-
03
Restricted access There is no open database or intermediary storage behind this site, drastically reducing the attack surface.
-
04
Scheduled destruction Data is deleted on a strict schedule outlined in our privacy notice, not when someone remembers.
Engineering and Security Controls in Build
Access Inheritance from approved core systems ensures access scope is not expanded in the application and AI layers.
Encrypting sensitive data during transit and storage, enforcing PII Masking policies, and maintaining documented audit logs.
Defining incident management scopes and SLAs with contractual precision to prevent any ambiguity during emergency handling.
Alignment with National Frameworks
Commitment to the Essential Cybersecurity Controls (ECC) issued by the National Cybersecurity Authority (NCA), Personal Data Protection Law (PDPL) requirements, and the SAMA Cybersecurity Framework for the financial sector.
Vulnerability Disclosure Policy
We welcome responsible security reports from researchers and specialists. If you discover any security vulnerability, please notify us directly via the security email: security@forefront-it.com, including sufficient details to reproduce the issue. We commit to responding and verifying within two working days.