Threat-modelfirst. Audit-readyalways.

SAMA-aligned, zero-trust by default. Reviewed by humans who care. We find the gaps before regulators — and before attackers — do.

security-posture

What "production-grade" actually means here.

auth

Identity & auth

OIDC + mTLS by default. Service-to-service identities are vaulted, rotated, and never share long-lived secrets. SSO integrations to NCA-compliant providers.

data

Data protection

Envelope encryption at rest. TLS 1.3 in transit. Field-level encryption for PII. KMS keys are customer-managed when regulators ask.

perimeter

Network & perimeter

Zero-trust segmentation. Egress is allow-listed. Every service speaks through an authenticated mesh — no "internal-only" assumptions.

audit

Audit & observability

Immutable, append-only audit logs. Structured events route to a SAMA-aligned SIEM. Every privileged action is replayable for compliance review.

compliance

Aligned with the rulebook.

SAMA
fintech / banking
NCA
national cyber
SDAIA
data & AI
PDPL
personal data
ISO 27001
info-sec mgmt
OWASP ASVS
appsec baseline

security-services

What we run.

01

Threat modeling

Whiteboard with your engineers, walk the data flow, identify trust boundaries. Output: a written threat model your CISO can sign and the audit team will accept.

02

Architecture review

Read your repo, your infra, your deploy pipeline. Find the gaps, write them up, prioritise by exploitability and blast radius.

03

Pen-test readiness

Make sure the test is worth running. We close the obvious holes first so the pen-test team can find the interesting ones.

04

Incident runbooks

Written, drilled, version-controlled. Your on-call team should know exactly what to do at 2am. We make sure they do.

scoreboard

What 14 days of operations looks like.

tuwaiq — sec/scoreboard
$ audit findings · 14d
0
$ secrets rotated · 14d
284
$ anomalies · auto-resolved
12
$ anomalies · escalated
0
$ patches applied
47
$ open critical CVEs
0

Ready to scope something real?

Discovery is one fixed-fee week. You walk away with an architecture doc whether or not we go further.

$ curl -X POST tuwaiqtech.ai/start

Start a project →