The AI-first GRC platform for the Kingdom's most regulated organizations — every risk, control and obligation in one clear view, with intelligence that runs entirely inside your own walls.
Legacy compliance software was built elsewhere, for elsewhere, and runs on someone else's cloud. Wathiq was built in the Kingdom, for the Kingdom — sovereign by design, not by configuration.
Wathiq links the entire GRC lifecycle so nothing lives in isolation. A control maps to a framework, carries its evidence, drives a risk, raises a finding, and rolls up to the board — automatically.
Policy lifecycle with versioning, committees, workflows and multi-stage approvals — mapped to the controls they satisfy.
A living register with 3×3–5×5 methodologies, FAIR-style monetary quantification, KRIs, scenarios and emerging-risk countdowns.
Pre-loaded NCA, SAMA, PDPL, ISO & NIST libraries with AI cross-mapping, maturity assessments and a full audit lifecycle.
Auto-tier vendors 1–4, dispatch tier-matched questionnaires, and collect answers through an isolated supplier portal.
Open the supplier portal →A unified incident hub with the PDPL 72-hour breach clock, cross-module lineage and AI-drafted narratives.
Awareness, phishing simulation and a behavioural human-risk index that posts training completions as live evidence.
Wathiq runs its AI on a model hosted inside your own infrastructure — CPU or GPU, on-premise or your private cloud. No prompt, no document, no regulated record is ever sent to an external API.
Strict multi-tenant isolation enforced at the database with row-level security, a tamper-evident audit trail, and phishing-resistant authentication — the assurances a regulated enterprise requires.
Single-command Docker inside your data centre — air-gap capable — or a containerized deployment to your own cloud. The platform and its AI always stay under your control, resident in the Kingdom.
Request a private demonstration and we'll walk your team through Wathiq on your frameworks, in your language, on your infrastructure.