Taqania

Regulatory Compliance

Cybersecurity and Compliance

Last updated: 23 August 2026

Data Sovereignty & Site Flow

We apply the principle of minimizing the attack surface and data protection responsibility from the ground up; our site does not retain unnecessary intermediary data, and all systems we build are subject to national cybersecurity controls.

  1. 01
    Direct, limited input The enquiry and career forms only. No tracking cookies, no advertising networks.
  2. 02
    Encrypted transit Hosting is managed via Vercel; form delivery via Resend. Both ensure end-to-end encryption during transit. ENCRYPTED IN TRANSIT
  3. 03
    Restricted access There is no open database or intermediary storage behind this site, drastically reducing the attack surface.
  4. 04
    Scheduled destruction Data is deleted on a strict schedule outlined in our privacy notice, not when someone remembers.

Engineering and Security Controls in Build

Access Inheritance from approved core systems ensures access scope is not expanded in the application and AI layers.

Encrypting sensitive data during transit and storage, enforcing PII Masking policies, and maintaining documented audit logs.

Defining incident management scopes and SLAs with contractual precision to prevent any ambiguity during emergency handling.

Alignment with National Frameworks

Commitment to the Essential Cybersecurity Controls (ECC) issued by the National Cybersecurity Authority (NCA), Personal Data Protection Law (PDPL) requirements, and the SAMA Cybersecurity Framework for the financial sector.

Vulnerability Disclosure Policy

We welcome responsible security reports from researchers and specialists. If you discover any security vulnerability, please notify us directly via the security email: security@forefront-it.com, including sufficient details to reproduce the issue. We commit to responding and verifying within two working days.