AI-Powered GRC Β· Built for Saudi Arabia & GCC

Compliance confidence.
Not compliance anxiety.

Arduredu automates evidence collection, risk management, audit preparation, and incident tracking across SAMA, NCA-ECC, ISO 27001, and 9 other frameworks β€” deployed on your own server in 30 minutes.

12+
Frameworks
600+
Controls
27+
Connectors
30m
To Deploy
All frameworks covered
SAMA CSF
NCA-ECC
NCA-CCC
NCA-DCC
SDAIA PDPL
ISO 27001
GDPR
NIS2
SOC 2
DORA
UAE-IA
PCI-DSS
See It In Action
Watch Arduredu in 2 minutes

See how Arduredu automates compliance evidence, manages risk, and prepares your organisation for SAMA and NCA audits β€” live on your own server.

βœ“ Live platform demo
βœ“ SAMA & NCA-ECC workflows
βœ“ AI evidence extraction
βœ“ Arabic RTL interface
Live Platform
Your compliance score,
updated in real-time
app.arduredu.com β€” Compliance Dashboard Β· Live
73%
SAMA Score
88%
NCA-ECC Score
3
Critical Issues
SAR 30M
Risk Mitigated
MFA enforced for all privileged users
SAMA-CSF-3.3 Β· NCA-ECC-2-2-3 Β· ISO-A.9
CRITICALEntra IDβœ“ PASS
Cybersecurity governance framework documented
SAMA-CSF-1.1 Β· NCA-ECC-1-1-4 Β· ISO-A.5
CRITICALAI Evidenceβœ— FAIL
NCA incident notification within 72 hours
NCA-ECC-5-1-5 Β· SAMA-CSF-5.3 Β· NIS2-Art.23
CRITICALIncidentsβœ— FAIL
Encryption of data at rest and in transit
SAMA-CSF-3.8 Β· NCA-ECC-2-4-1 Β· ISO-A.10
CRITICALPurviewβœ“ PASS
Vulnerability management programme active
SAMA-CSF-3.12 Β· NCA-ECC-2-6-1 Β· ISO-A.12
HIGHTenableβœ“ PASS
The Problem
GCC compliance is broken

Banks, government entities, and critical infrastructure operators across the GCC face growing regulatory pressure β€” with tools that were never built for local frameworks.

πŸ“‹

Manual Evidence Collection

Compliance teams spend weeks collecting screenshots, logs, and documents from 15–20 different systems before every SAMA or NCA assessment.

πŸ”€

No Single View

Risk, compliance, audit, policy, and incidents live in separate tools. No CISO can answer "Are we SAMA-compliant right now?" with confidence.

⏰

Audit Anxiety

Organisations discover gaps during SAMA or NCA assessments β€” not before. By then it's too late to fix, and findings lead to sanctions.

πŸ’Έ

Tools Not Built for GCC

Global GRC tools (ServiceNow, Archer, MetricStream) cost millions, take 6–12 months to deploy, and still don't cover SAMA or NCA natively.

Platform Capabilities
A complete GRC platform.
Built for the GCC.
πŸ“Š

Live Compliance Scoring

Real-time compliance score per framework, updated continuously as your environment changes. See exactly which controls pass, fail, or need evidence β€” across all 12 frameworks simultaneously.

Real-time
πŸ€–

AI Evidence Extraction

Upload any policy document, audit report, or certificate β€” Arduredu's AI engine automatically extracts evidence and maps it to the right controls with confidence scoring. No manual mapping needed.

AI-powered
⚠️

Risk Management

Visual 5Γ—5 risk heat map, risk appetite settings by category, and full treatment workflow (Mitigate, Accept, Transfer, Avoid). Assign risk owners, set due dates, and track financial exposure.

Heat Map
🚨

Incident Management

Full incident register with NCA 72-hour notification countdown timer. Automatic sync from ServiceNow and Jira. Log notifications to NCA, SAMA, and SDAIA with reference number tracking.

NCA-ECC-5-1
πŸ”

Audit Management

Manage internal and external audit programmes, findings, and corrective action plans (CAPs). Annual audit planning calendar, external auditor register, and one-click evidence package export for regulators.

CAPs & Calendar
πŸ“„

Policy Management

Full policy lifecycle with approval workflow β€” Draft, Review, Approve, Publish, Retire. Version control saves every change. Staff acknowledgement tracking. GRC Officer and CEO sign-off built in.

Approval Workflow
πŸ“‹

SAMA DCQ Auto-Fill

All 244 SAMA Data Collection Questionnaire questions pre-loaded. Answers auto-populated from connected systems. Export to Excel in the exact SAMA submission format β€” reducing weeks of work to hours.

244 Questions
πŸ—‚οΈ

Evidence Centre

Full evidence registry with gap analysis, expiry tracking, and bulk evidence requests. Know exactly what evidence you have, what's missing, and what's expiring β€” per framework, per control.

Audit-ready
🏒

Vendor Risk Management

Track all third-party vendors with risk tier classification, SAMA security clause compliance, DPA status, contract expiry alerts, BitSight and SecurityScorecard continuous monitoring.

SAMA-13
πŸ—ΊοΈ

Gap Analysis

One-click gap analysis showing every failing control, regulatory reference, AI-generated remediation guidance, and what evidence is needed. Board and auditor ready with export.

Board-ready
πŸ”’
On-Premise Deployment
Your data never leaves your server
πŸ€–
AI Evidence Engine
Automatically maps documents to controls
🌍
Arabic RTL Interface
Full Arabic support for GCC teams
πŸ“‹
Full Audit Trail
Every action timestamped and logged
⚑
30-Minute Deployment
One command installs everything
Regulatory Frameworks
One platform. Every regulation
that matters in the GCC.

Global tools don't cover SAMA, NCA-ECC or SDAIA natively. Arduredu is built specifically for GCC regulatory requirements β€” plus all major international frameworks.

SAMA CSF

Saudi Central Bank Cybersecurity Framework

Mandatory for all financial institutions supervised by SAMA. Full control mapping with automated evidence from 27+ connectors and SAMA DCQ auto-fill.

Saudi Arabia169 controlsLive
NCA-ECC

NCA Essential Cybersecurity Controls

Saudi Arabia's national cybersecurity framework β€” mandatory for government entities, banks, and critical sectors. Includes NCA 72-hour incident notification tracking.

Saudi Arabia80 controlsLive
NCA-CCC

NCA Cloud Cybersecurity Controls

NCA framework for cloud service adoption in Saudi Arabia. Covers cloud governance, data classification, and shared responsibility model compliance.

Saudi Arabia97 controlsLive
NCA-DCC

NCA Data Cybersecurity Controls

NCA framework for data classification, data lifecycle management, and data protection requirements for Saudi organisations.

Saudi Arabia62 controlsLive
SDAIA PDPL

Saudi Data & AI Authority β€” Personal Data Protection

Saudi Arabia's Personal Data Protection Law. Covers consent, cross-border transfers, breach notification, and data subject rights.

Saudi Arabia38 controlsLive
ISO 27001

ISO/IEC 27001:2022 Information Security

Global standard for information security management. Opens enterprise procurement internationally. 93 controls mapped to Annex A requirements.

Global93 controlsLive
GDPR

General Data Protection Regulation

EU data privacy law β€” fines up to €20M or 4% of global turnover. Essential for any organisation handling EU personal data or with EU operations.

EU47 controlsLive
UAE-IA

UAE Information Assurance Standard

UAE's national information assurance framework for government and critical infrastructure. Aligned with UAE Cybersecurity Council requirements.

UAE55 controlsLive
NIS2 Β· DORA Β· SOC2 Β· PCI-DSS

International Frameworks

NIS2 (EU cybersecurity), DORA (EU financial resilience), SOC 2 (US enterprise), and PCI-DSS v4 (payment card security) β€” all available in the same platform.

EU Β· USA Β· Global426 controlsLive
System Connectors
Connect your entire security stack

27+ connectors with read-only access. Evidence collected automatically. One scan updates compliance scores across all frameworks simultaneously.

πŸ”
Azure Entra ID
Identity & IAM
πŸ”‘
CyberArk PAM
Privileged Access
πŸ”
Tenable.io
Vulnerability
πŸ¦…
CrowdStrike
EDR
🟣
SentinelOne
EDR
πŸ”΅
IBM QRadar
SIEM
πŸ”·
MS Sentinel
SIEM
🏷
MS Purview
Data Classification
πŸ“·
Genetec CCTV
Physical Security
πŸšͺ
Lenel S2
Access Control
πŸ‘₯
SAP SuccessFactors
HR & Training
⭐
BitSight
Vendor Risk
☁️
AWS
Cloud
πŸ”·
Azure Cloud
Cloud
πŸ”΅
Google Cloud
Cloud
πŸͺŸ
Microsoft 365
Productivity
πŸ›‘οΈ
MS Defender
Security
πŸ“±
Intune
Device Mgmt
πŸ”
Okta
Identity
🎫
ServiceNow
ITSM
πŸ”΅
Jira
ITSM
πŸ™
GitHub
Code Security
πŸ”΄
Oracle Cloud
Cloud
πŸ“Š
SecurityScorecard
Vendor Risk
πŸ–₯️
On-Premise
Linux Agent
🏦
SAP ERP
Finance
πŸ”₯
Firewall / NGFW
Network
Deployment
On your server.
In 30 minutes.

Arduredu deploys on-premise β€” your data never leaves your environment. Docker-based installation, one command, fully automated.

1

Request Access

Submit your download request. Arduredu reviews and provides a secure, time-limited download link within 24 hours.

2

Download Package

Two packages: Application Server and AI Server. Extract and configure your environment file with your organisation details.

3

Run Installer

One command: ./install.sh β€” deploys all services, configures SSL, and starts the platform automatically.

4

Connect & Score

Connect your existing security systems. Compliance scores appear immediately. Evidence collected automatically from day one.

Get in Touch
Let's talk compliance

Ready to see Arduredu in action?

Book a live demo, request a pilot deployment, or ask us anything about SAMA, NCA-ECC, or GCC compliance. We respond within 24 hours.

πŸ“§
sales@arduredu.com
🌐
arduredu.com
πŸ“
Stockholm, Sweden Β· Riyadh, Saudi Arabia
On-Premise Enterprise

Arduredu is an enterprise on-premise platform. All pricing is customised per organisation. Contact us for a tailored proposal.

Request Download Access β†’
βœ“ Message sent! We'll be in touch within 24 hours.

Are you audit-ready
right now?

Most organisations can't answer that question honestly. Arduredu makes sure you always can β€” across SAMA, NCA-ECC, and every framework that matters in the GCC.

Book a Demo β†’
About Arduredu

Built by compliance practitioners,
for compliance practitioners

We understand the pressure of regulatory audits, the complexity of GCC frameworks, and the gap between what compliance teams need and what legacy tools deliver.

πŸ›‘

We invented Arduredu to solve a problem no existing tool could β€” making SAMA, NCA-ECC, and GCC regulatory compliance truly automatic.

🎯
Our Mission

To make regulatory compliance effortless for every organisation in the GCC and beyond β€” through automation, intelligence, and deep local regulatory knowledge.

πŸ‘
Our Vision

To become the most trusted GRC platform in the GCC market and beyond β€” the platform that every CISO, Compliance Officer, and Board member relies on before every regulatory audit.

πŸ†
Our Values

Transparency in everything we build. Accuracy in every compliance score. Respect for the complexity of regulatory work β€” and relentless innovation to make it simpler.

Arduredu at a Glance
12+
Frameworks
600+
Controls Automated
27+
Connectors
Sweden
Headquartered