Introducing Mavs AI Business Sensitive Data Detection.Read The Announcement →

    Use Frontier AI And
    Keep Your Data Sovereign
    for PDPL-Compliance

    Use OpenAI, Claude or Gemini under Saudi and UAE data protection law with the Mavs AI runtime control layer for data sovereignty.

    World map showing a sovereign shield protecting data in the GCC region
    Built by enterprise cybersecurity experts

    What PDPL Asks of You
    and How Everyday Prompts Become Breaches

    Feature preview
    • 01 — Keep personal data inside the country.

      SAR 5M max penalty, doubled on repeat

      Personal data can leave Saudi Arabia or the UAE only under strict conditions: the destination country must be approved by the regulator, or the transfer must be covered by a contract that protects the data, and you must assess the risk first. UAE sector rules go further: health data may not be stored or processed outside the UAE, and the Central Bank requires customer and transaction data to stay in the country. Risk: Every prompt to a model hosted abroad is a cross-border transfer. On a public LLM there is no contract behind it. On the enterprise tool there is, but it cannot tell you which personal data left in which prompt. Either way, you cannot show a regulator what left or where it went.

    • 02 — Respect purpose limitation and data minimisation.

      SAR 5M max penalty, doubled on repeat

      Purpose limitation means personal data can be processed only for the specific purpose the person was told about when it was collected. Data minimisation means you may use only as much of it as that purpose requires. Anything more needs a fresh legal basis. Risk: A customer record collected to service an account was not collected to be summarised by a third-party model. When an employee pastes the whole record into a chat app, the data is processed for a purpose the customer never agreed to, and far more of it than the task needed.

    • 03 — Honour requests to see, correct or destroy data.

      30 days to respond

      Anyone whose data you hold can ask to see it, have it corrected, or have it destroyed. You have a fixed time to respond, and the regulator can act on any failure. Risk: Once personal data reaches a third-party LLM, it sits in chat history and vendor logs you cannot search or delete. You can destroy the record on your own systems and still be unable to honour the request.

    • 04 — Demonstrate technical safeguards on personal data.

      SAR 3M and up to 2 years' imprisonment for unlawful disclosure of sensitive data

      Personal data must be protected by security controls you can show the regulator: encryption, access control, logging, monitoring and retention limits. Health, financial and biometric data carry the heaviest penalties when those controls fail. Risk: Sending real personal data to an LLM fails this twice. It leaves the reach of your controls, then sits in the provider's caches and logs where none of your safeguards apply. A clinician asking a model about a real patient has taken the record outside every control you could show.

    • 05 — Respond to breaches inside the clock.

      72 hours to notify SDAIA

      If personal data is breached, Saudi Arabia requires you to notify SDAIA within 72 hours and the affected individuals without undue delay. The UAE requires notification to the Data Office as soon as you become aware. The notification has to say what data was exposed and whose. Risk: AI chat tools keep no record of which personal data left in which prompt. Without per-prompt logs, establishing the scope of a breach means asking employees what they typed.

    Residency Is Where Data Sits
    Sovereignty Is Who Controls It

    Chat interface exposing personal data transfers and the three copies created outside your control under PDPL

    Three Pillars of the Mavs AI Control Layer for PDPL Compliance

    SYNTHETIC SUBSTITUTION
    AT THE PROMPT BOUNDARY

    Sensitive data in the prompt is replaced with realistic synthetic stand-ins: a name for a name, an ID for an ID. The model answers as it would have with the real data, and the real values are restored before the user reads it. The provider sees only the synthetic version.

    Mavs AI substituting a name and national ID with synthetic values before a prompt reaches the model, then reversing the substitution in the response.

    A PRIVATE TENANT
    HOSTED IN YOUR COUNTRY

    Real values, substitution mappings and the Mavs engine run in a private tenant in the country you choose. Only the synthetic prompt crosses the border, so residency and sovereignty hold for every model your teams use.

    Tenant Settings panel showing Region set to Riyadh, Saudi Arabia, with real values and substitution mappings staying in the tenant while the synthetic prompt crosses the border.

    GOVERNANCE
    AND AUDIT TRAIL

    Guardrails act on the sensitive data inside a prompt rather than blocking the prompt, and you set them per team. Every prompt, substitution and response is logged immutably, so when the regulator asks how a transfer was controlled, the answer is in your own log.

    An audit log entry showing timestamp, user, model, PII detected, substituted count, response tokens and time for one prompt.

    One Control Layer For Every Way Your Enterprise Uses AI

    Mavs Secure ChatRead MoreClaude DesktopSecured by MavsRead More
    AI in BrowserComing soon
    Agentic AppsContact us for API docs

    How we Ride?

    PDPL Is About Keeping Control of the Data

    The usual fixes give up either the data or the model. Mavs AI helps you keep both.

    RequirementMavs AISelf-hosted modelProvider-hosted model in-regionOther AI-DLP guardrails

    Personal data stays in the country

    Only synthetic values leave.
    Yes. Nothing leaves your environment.
    Stays in-country, held by the provider.
    Only if the prompt is blocked or the value is redacted. Bussiness sensitive data usually leaks.

    Model reasons with full context

    Realistic stand-ins keep the context intact.
    Yes, the model reasons over full context.
    Yes, the model reasons over full context.
    Redacted or masked values cannot be compared or summed. Blocked prompts get no answer at all.

    Choice of frontier model

    Any: OpenAI, Claude, Gemini and others.
    Open-weights models only. The leading frontier models are not available to self-host.
    Only that provider's models, and only once they are made available in-country. Newest releases usually arrive later.
    Any.

    Audit evidence per prompt

    Immutable log of every prompt, substitution and response.
    Only if you build the logging yourself.
    Provider-dependent.
    Yes. Prompts, responses and actions taken are logged.

    Deleting a customer's data on request

    The provider received only synthetic values, so there is nothing of the customer's to delete.
    Yes. You hold every copy.
    The provider holds a copy in its own systems. You have no way to prove it was deleted.
    Redacted data does not reach the provider, so there is nothing to delete.

    What it costs you

    One control layer across every surface.
    GPU infrastructure, a team to run inference, and a capability gap against frontier models.
    Tied to one provider's models, roadmap and pricing.
    Productivity when it blocks, output quality when it masks.

    Frequently Asked Questions

    • Which laws does this page cover?

      The Saudi Personal Data Protection Law, enforced by SDAIA and in force since September 2023, and the UAE's Federal Decree-Law No. 45 of 2021, overseen by the UAE Data Office. Qatar (Law No. 13 of 2016), Bahrain (Law No. 30 of 2018) and Oman (Royal Decree 6/2022) follow the same pattern: purpose limitation, individual rights, and restrictions on moving personal data out of the country. Mavs applies the same control regardless of which one you answer to.

    • Is sending a prompt to a model hosted abroad a cross-border transfer?

      Yes, if the prompt contains personal data. The Saudi Transfer Regulations and UAE Articles 22 and 23 apply to the act of transferring, not to where the data is stored afterwards. A prompt with a National ID or Emirates ID in it is a transfer the moment it leaves your network.

    • Where does Mavs run?

      In a private tenant hosted in the GCC, or inside your own VPC or private environment. The risk engine, your policies, the substitution mappings and the audit log stay in that tenant. Only the synthetic prompt goes to the model.

    • Does the model provider still receive personal data?

      No. Personal and sensitive values are replaced with synthetic stand-ins before the prompt leaves your environment. The provider receives a prompt that reads naturally and contains no real personal data, so there is nothing for it to retain, log or train on.

    • Does it work with OpenAI, Claude and Gemini hosted outside the region?

      Yes. That is the point. Your teams use the frontier models they want, hosted wherever the provider hosts them, and the data that reaches those models is synthetic.

    • Does Mavs recognise national ID numbers and other local identifiers?

      Yes. Saudi National ID and Iqama numbers, Emirates ID, Qatar ID, Bahrain CPR and Omani civil numbers, along with IBANs, phone numbers, names, addresses, dates and amounts. Mavs reads the prompt as language rather than matching patterns, so it also finds sensitive values that have no fixed format.

    • Does this cover health and banking data under UAE sector rules?

      The same mechanism applies. Health records and transaction data are substituted before the prompt leaves the UAE, and every prompt is logged. Mavs supplies two things a regulator asks for: enforced controls on what leaves, and evidence of every event. Your broader obligations under Federal Law No. 2 of 2019 and the Central Bank standards remain yours.

    • Can Mavs AI help us with intellectual property and other business-sensitive data?

      Yes. Deal codenames, unannounced pricing, bid figures, unreleased roadmap, product designs and key account lists are not personal data, so pattern-based tools do not see them. Mavs reads the prompt as language, judges what is sensitive in the context of your business, and substitutes those values the same way it does personal data. A fund can have a frontier model summarise a term sheet without the counterparty names leaving the country.

    • How is this different from waiting for a sovereign model?

      An in-region model keeps the data in the country, but it is a bet on a smaller set of models at a higher price, and the provider is still inside your data path. Mavs keeps the data in the country and lets you use any model. Where you already run an in-region model, Mavs adds the per-prompt policy and audit layer on top.

    • Does Mavs sign a data processing agreement?

      Yes. Our standard DPA covers processor obligations under the Saudi PDPL and the UAE Decree-Law, sub-processor controls, breach cooperation, and confirmation that customer data is not used for training.

    • How is Mavs deployed, and how long does it take?

      Mavs is a runtime control layer over API, hosted in a private tenant in the country you choose or within your own environment. For employees, Mavs Secure Chat runs in the browser with nothing to install, and sign-in goes through your existing identity provider. For apps and agents, integration is via API. Most enterprises are live within a few hours.

    Book A Demo

    RIDE WITH US!