SECURITY & COMPLIANCE

Built for the people who can say no.

Compliance officers do not sign. They veto. This page names every control in full, and shows you evidence you can verify yourself, offline, without us.

The controls, named in full.

TENANT ISOLATION

Sealed at the database

Postgres row-level security on every tenant-scoped table. Data is segregated at the database, not just the application layer.

AUTHENTICATION

Phishing-resistant by design

AAL2 on every protected route. QR scan-to-approve and WebAuthn passkeys. No SMS or email OTP, per CBUAE Notice 2025/3057.

GOVERNED AI

Surfaces, never decides

AI flags inconsistencies and adverse findings. A human makes every approval. Aligned with UAE Decree-Law 10/2025.

DATA PROTECTION

Four regimes, one design

GDPR, UAE PDPL, DIFC, and ADGM. Document access is served over signed, logged URLs. TLS 1.2 or higher in transit.

EVIDENCE

Verifiable without us

Ed25519 signatures over a SHA-256 hash chain, stamped by an independent RFC3161 authority. Checkable offline, years later.

AUDIT TRAIL

Tamper-evident by default

Every state-changing action is hash-chained. Document access logs are retained for seven years.

Proof you can check yourself.

An evidence pack is not a screenshot of trust. It is a signed, timestamped, hash-chained record you can verify with standard tools, on your own machine, with no live service. If we disappeared tomorrow, your proof would still hold.

AI surfaces. A human decides. The evidence outlasts both. Nothing on Exedra Gate auto-approves a person, a company, or an offering. The platform records what happened so a reviewer, an auditor, or a regulator can reconstruct it later.

Send us your security questionnaire.

We answer compliance and security diligence directly. Tell us who you are and we will route you to the right person.

Compliance teams: compliance@exedragate.com · Security: security@exedragate.com