Skip to content
Now taking design partners.Roadmap →

UAE IA / NESA, Saudi NCA ECC

Compliance evidence · Gulf

AI-agent, MCP, and software inventory, exposure, and incident-response evidence for regulated entities in the UAE and Saudi Arabia, with regional or self-hosted deployment.

Request evidence packMapping updated

What we mean by "produces evidence"

Sekeye does not grant NESA or NCA compliance. It produces the inventory, exposure, and incident-response artefacts these regimes require, covering the AI agents and MCP servers running across your hosts as well as the software layer beneath them, inside your data-residency perimeter and with self-hosted deployment where mandated.

Compliance evidence supports the case; it is not the case. The operational problem is that AI agents run on laptops and servers with credentials and autonomy, and the regimes below already ask you to inventory and control exactly that class of asset.

UAE Information Assurance (IA) / NESA

  • Asset inventory including software. The AI-agent, MCP, skill, and local model layer alongside the self-installed software layer that underpins the T3 controls.
  • Vulnerability management with a defensible remediation trail. Findings, closure states, and credential-rotation checklists, including AI-infrastructure CVEs.
  • Data residency and sovereign deployment. Self-hosted mode supports Gulf sovereignty requirements, with no model inference leaving the perimeter.

Saudi NCA ECC (Essential Cybersecurity Controls)

  • Asset management. Fleet inventory of the AI-agent and MCP layer plus the self-installed software layer, across laptops and servers.
  • Vulnerability management. Continuous CVE match including AI-infrastructure and KEV-listed issues, with closure tracking.
  • Incident management. Campaign scope, per-host findings, and per-agent blast radius feed the incident timeline.