Skip to content

Security at Wethaq

Your financials are the product. Protecting them is the platform.

Wethaq ingests confidential financial statements and produces credit judgments — a combination that makes security a first-class product requirement, not a checkbox. This page describes, plainly, how your data is stored, processed, and protected.

Hosted in Saudi Arabia PDPL-aligned Encrypted in transit & at rest Tamper-evident audit trail
01

Data residency in the Kingdom, aligned with the PDPL

Wethaq runs on infrastructure in Saudi Arabia, and your documents and financial data stay in the Kingdom by default. Processing is aligned with the Saudi Personal Data Protection Law (PDPL): we maintain a record of processing, honor data-subject rights, and treat any movement of data outside the Kingdom as an explicit, recorded decision — never a silent default.

  • Documents and financial data hosted in-Kingdom by default
  • A maintained PDPL record of processing
  • Cross-border transfer only as a documented, gated exception
  • Data minimization: we keep what the analysis needs, no more
02

Encryption in transit and at rest

Every connection to Wethaq is encrypted with TLS, and stored data — documents, databases, and backups — is encrypted at rest. Secrets live in a secret manager, never in code.

  • TLS on every connection, with HSTS
  • Documents and databases encrypted at rest
  • Secrets kept in managed stores, never in the codebase
03

Private storage — no public URLs, ever

Uploaded statements go into private object storage that has no public access. Files are checked on arrival — real PDF signatures, size caps, content validation — and originals are kept immutable so every extracted figure remains traceable to its source page.

  • Private object store; nothing is publicly addressable
  • Access only through signed, expiring links
  • Uploads validated (true PDF check, size caps) before storage
  • Original documents kept immutable for provenance
04

Tenant isolation and least-privilege access

Every company, document, and analysis belongs to exactly one organization, and that ownership is enforced in the data layer itself — queries are scoped so one customer can never see another's records. Inside your organization, role-based access control applies least privilege, and accounts can be protected with two-factor authentication and passkeys.

  • Organization-scoped queries enforced at the framework level
  • Role-based access control with least privilege
  • Two-factor authentication and passkey sign-in
  • Rate limiting on authentication and upload endpoints
05

A tamper-evident audit trail

A credit product needs evidence, not just logs. Wethaq records consequential actions — uploads, corrections, analyses, scores, exports, access — in an append-only audit log whose entries are chained with cryptographic hashes, so history cannot be silently rewritten.

  • Append-only log of uploads, corrections, scores, and exports
  • Entries hash-chained for tamper evidence
  • Every score records the scorecard version that produced it
  • Long-term retention for dispute resolution and review
06

AI reads documents. A deterministic engine computes the numbers.

Wethaq uses AI where it is strong — reading documents and mapping line items — and keeps it away from where it must not be: the math. Every ratio, subtotal, and score is computed by a deterministic, rules-based engine, validated with accounting-identity and reconciliation checks. Your statements are processed under enterprise terms and are not used to train models. Where an AI step involves an external provider, that data path is a deliberate, documented, and audited decision — never an accident.

  • Deterministic calculation engine — AI never computes or alters figures
  • Automatic balance and reconciliation checks on every spread
  • Your documents are not used to train AI models
  • Any external AI processing is a documented, gated, audited decision
07

Sharing and verification you stay in control of

When you share a report, you share a revocable link — not a copy you can never take back. Printed and exported reports carry a QR verification code that anyone can scan to confirm the report is genuine and unmodified, checked against a cryptographic fingerprint of its contents.

  • Report share links are revocable at any time
  • Shared pages are throttled and serve frozen snapshots
  • QR verification confirms authenticity against a SHA-256 fingerprint
  • Every verification and share visit is recorded
08

What Wethaq is — and what it is not

Wethaq is an analytical decision-support tool. It is not a licensed credit rating agency, not a credit bureau, and not a lender. It complements SIMAH bureau data rather than replacing it: SIMAH reports how a company has borrowed and repaid; Wethaq analyzes what its financial statements say about its health today. Decisions remain yours.

  • Decision support — not a licensed rating agency or bureau
  • Complements SIMAH bureau data; does not replace it
  • Transparent, rules-based scoring you can inspect

Found a vulnerability?

We take reports from security researchers seriously. If you believe you have found a vulnerability in Wethaq, email us with enough detail to reproduce it — we will acknowledge your report, investigate, and keep you informed.

Please do not access data that is not yours or disrupt the service while researching.

Analyze with confidence.

Whether you need one report on one company or a platform for your whole credit team, your data gets the same protection.