Projex Labs Products are coming "very soon"
← Back to home
Trust

Data residency. Compliance-native. Long-horizon stewardship.

Projex Labs was founded in Saudi Arabia and built from day one to operate inside the PDPL / NCA / SDAIA / SFDA perimeter. We are literate with SAMA, CMA, ZATCA, and every authority our customers answer to. We are not retrofitting compliance onto cloud-first architecture — we designed the architecture around compliance.

Saudi data stays Saudi

Our default deployment posture is in-kingdom. Hakeem (clinical AI) runs on hospital-premise edge nodes — zero data leaves the building. Gov-facing ventures are architected for in-kingdom data planes by default.

Compliance-native, not retrofit

We speak PDPL, NCA, SDAIA, SFDA, SAMA, CMA, ZATCA natively. Our business-rule layer (BR-004) requires every product to name the exact regulatory framework it operates under.

Open-source auditable

Our product cores are open source. Independent auditors, security researchers, and government review teams can read the code. Trust that can be inspected is trust that scales.

Stewardship beyond launch

We stay with what we build. Our equity model means we don't ship-and-leave. Long-horizon stewardship is priced into the engagement, not tacked on.

Sovereignty by design. Compliance by construction.

Every venture and product we build is designed from day one to operate within the regulatory boundaries our customers answer to. These are not badges earned by audit — they are architectural commitments made before a line of code is written.

PDPL

Personal Data Protection Law

Royal Decree M/149. Saudi personal data stays in Saudi. Cross-border transfer rules baked into architecture.

NCA

National Cybersecurity Authority

Essential Cybersecurity Controls (ECC) + Cloud Cybersecurity Controls (CCC). Not retrofitted — designed-in.

SDAIA

Saudi Data & AI Authority

National Data Management Office (NDMO) standards and AI ethics framework. Our ventures ship aligned with the national data governance posture.

SAMA

Saudi Central Bank

For fintech and payments ventures (e.g. Rabbit): SAMA sandbox alignment + anti-fraud + AML/KYC by construction.

SFDA

Saudi Food & Drug Authority

For health ventures (e.g. Hakeem): SFDA registration pathway + clinical data handling aligned with PDPL + pharmacovigilance-aware.

ZATCA

Zakat, Tax & Customs Authority

For commercial ventures: ZATCA e-invoicing (Fatoora) compliance baked into every B2B transaction.

What you can ask for.

Because sovereignty is designed-in, not audited-in, we maintain artefacts available on request — not locked behind an enterprise sales motion.

Architecture Decision Records (ADRs)

Every sovereignty + compliance decision is traced to an ADR visible on request.

Data residency map

For every venture: where data lives, how it moves, who can access it, how long it stays.

Incident response runbook

NCA-aligned IR procedures, publicly readable structure, on-request specifics.

Open-source code review trail

Every change traceable to a UC. Every UC traceable to a business rule. No black boxes.