# Sovereign Legal Compliance: Dike

_Last updated: August 21, 2026_

Dike provides the verified MENA legal source layer for artificial intelligence. We engineer our platform with sovereign legal alignment, data protection compliance, and regulatory transparency, ensuring enterprise legal departments, financial institutions, and government bodies can safely ground AI systems in official MENA statutory authority.

## 1. MENA Regional Regulatory Frameworks

Dike is designed specifically for organizations operating under sovereign Middle East legal frameworks:

- **Kingdom of Saudi Arabia (KSA):**
  - Aligned with the **Personal Data Protection Law (PDPL)** enacted by Royal Decree No. (M/19) and SDAIA executive regulations.
  - Controls mapped to the **National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC-1:2018)**.
  - Authentic statutory indexing of Umm Al-Qura official gazette and Royal Decrees with strict legislative hierarchy.
- **United Arab Emirates (UAE):**
  - Compliant with **Federal Decree-Law No. 45 of 2021** regarding Personal Data Protection.
  - Interoperable with **DIFC Data Protection Law No. 5 of 2020** and **ADGM Data Protection Regulations 2021**.
  - Authentic resolution of Federal Supreme Court principles and federal statutory decrees.
- **Arab Republic of Egypt:**
  - Adherent to **Law No. 151 of 2020** promulgating the Personal Data Protection Law.
  - Governed in accordance with National Telecommunications Regulatory Authority (NTRA) and Cybercrime Law No. 175/2018.
  - Comprehensive indexing of Al-Jarida Al-Rasmiyya (Official Gazette) and Court of Cassation rulings.

## 2. Sovereign Data Processing Commitments

- **Data Processor Role:** Dike acts solely as a secure data processor for customer queries. We process customer payloads strictly for retrieval and grounding without retaining data for secondary model training.
- **Cross-Border Transfer Controls:** Standard Contractual Clauses (SCCs) and regional data transfer agreements available for cross-border enterprise integrations.
- **Localized Cloud Deployment:** Support for dedicated enterprise tenant isolation in approved Middle East cloud availability zones (Saudi Arabia, UAE, Egypt).

## 3. Enterprise Compliance Artifacts Vault

Enterprise legal, risk, and security teams can request pre-compiled compliance documentation and custom agreements directly from our compliance office:

- **Enterprise Data Processing Addendum (DPA):** Ready-to-execute DPA with standard MENA cross-border transfer provisions. Contact [compliance@dike.it.com](mailto:compliance@dike.it.com?subject=Enterprise%20DPA%20Request).
- **SOC 2 Type II Alignment Summary:** Security, Availability, and Confidentiality control matrix mapping. Contact [compliance@dike.it.com](mailto:compliance@dike.it.com?subject=SOC%202%20Alignment%20Summary%20Request).
- **Vendor Risk Questionnaires (CAIQ / SIG Lite):** Pre-completed consensus assessment questionnaires for enterprise procurement. Contact [compliance@dike.it.com](mailto:compliance@dike.it.com?subject=Security%20Questionnaire%20Request).
- **Architecture & Grounding Whitepaper:** In-depth technical whitepaper on citation graphs and statutory verification engines. Contact [compliance@dike.it.com](mailto:compliance@dike.it.com?subject=Security%20Whitepaper%20Request).

For infrastructure security controls, TLS 1.3 encryption, and vulnerability disclosure policies, see our [Security Architecture](/security) trust center.
