Whitepaper
Mahsumah Cloud — Security & Operations
A transparent technical overview of our operating, security, and compliance model — what we actually do, and what we do not claim yet.
Version 1.0 — August 2026
1. What Mahsumah Cloud is
Mahsumah Company is registered in the National Personal Data Protection Register and registered as a Technology Enterprise with the Communications, Space and Technology Commission (CST). Mahsumah Cloud is being developed as a Saudi Managed PaaS with a compliance roadmap toward CST Cloud Computing Registration and ISO/IEC 27001 readiness.
Mahsumah Cloud is a Saudi cloud application platform (managed PaaS) that hosts and operates websites and web apps inside the Kingdom, with domains, SSL, backups, monitoring, and support managed from a single portal.
2. Positioning: Saudi Managed PaaS
We present the platform as a Managed Saudi PaaS: the customer selects a plan, pays, connects a GitHub repository, and the project is built and deployed automatically to a subdomain with SSL (Node and static apps), tracked in their dashboard. Migrations and PHP hosting are handled by our team. We do not claim full automation of every path.
3. Current operating model
Infrastructure runs on cloud compute inside Riyadh, with a dedicated isolated run node for customer code. Initial deploys from GitHub are automated (a resource-limited isolated build, then a non-root container behind Nginx with SSL), while migrations and PHP hosting are team-assisted, and sensitive actions are recorded in an append-only audit log.
4. Customer portal
Each customer has a portal showing projects, domains, billing and invoices, team and roles, activity log, notifications, and support — bound to real data or honest empty states, with no mock data.
5. Admin portal
Our team uses an admin portal that is the operational source of truth: organizations, customers, orders, subscriptions, invoices, deployments, domains, tickets, operations, staff and roles, and the audit log.
6. Authentication, MFA & RBAC
Sessions use a signed token with a bounded lifetime. SMS two-factor is required for our staff. Role-based access control is enforced server-side on every sensitive action in both the customer and admin portals — never relying on UI hiding.
7. Customer data separation
The platform is multi-tenant with organization-level isolation: every project, subscription, invoice, and ticket belongs to an organization, and a user cannot see another organization's data. Membership and permission are verified server-side.
8. Organizations & teams
Each customer owns an organization (workspace) with roles: Owner, Admin, Developer, Billing, Viewer. Owners/Admins can invite members, change roles, and remove — with every change recorded in the audit log.
9. Billing & payments — Moyasar, VAT & SAR
Prices are shown in Saudi Riyals and billed annually with 15% VAT added where applicable. Payments are processed through the Moyasar gateway; we do not store card data. A successful payment creates linked records: customer, order, subscription, invoice, project, operation, and audit entry.
10. Automated GitHub deployments
Initial deploy from a GitHub repository is fully automated for Node and static apps: the project is built in a resource-limited isolated sandbox, then run as a non-root container behind Nginx with SSL and a subdomain — with no human in the loop. Automatic redeploy on push and branch previews are still rolling out.
11. Monitoring & incidents
Service availability is monitored automatically (every five minutes) and the ops team is alerted when an issue is detected. Status is shown on a public status page. Response targets are stated as goals, not guarantees.
12. Backup & recovery
Daily automated backups of platform data are captured on Riyadh hosts with a defined retention window; this control-plane snapshot is not a per-site customer backup — daily per-site content backups run on managed cPanel/WordPress hosting. Traffic is encrypted with TLS certificates issued and renewed automatically for every domain.
13. Subprocessors
We list only confirmed vendors:
- Moyasar — Payment processing (checkout & invoices) (Saudi Arabia)
- Microsoft (Microsoft 365 / Graph) — Transactional email (account, order, and support notifications) (Global (Microsoft 365))
- Huawei Cloud (ECS) — Infrastructure hosting (compute) for the platform and customer sites (Riyadh, Saudi Arabia)
- SMS provider — SMS notifications — account alerts, operations, security, verification, and operational notices (Saudi Arabia)
14. Registrations & compliance roadmap
Active official registrations:
- National Personal Data Protection Register — 3260005644
- CST Technology Enterprise Registration — RI26-2188 (until 2027-04-01)
Compliance roadmap (honest statuses, no certification claims):
- National Personal Data Protection Register — Active
- CST Technology Enterprise Registration — Active
- CST Cloud Computing Registration — In preparation
- ISO/IEC 27001 (Information Security) — Readiness in progress
- ISO 22301 (Business Continuity) — Planned
- ISO/IEC 20000-1 (IT Service Management) — Planned
- SOC 2 — Future roadmap
15. Current limitations & what we do not claim yet
- We do not claim CST Cloud Computing registration — it is in preparation.
- We do not claim ISO 27001 or any other certification — readiness is in progress/planned.
- Initial GitHub deploys are automated (Node & static apps), but we do not claim full automation of every path — per-push redeploy, migrations, and PHP hosting are not fully self-serve yet.
- We do not make contractual availability commitments — figures are operational goals, not guarantees.
- We are not a data-center operator; we rely on a cloud compute provider inside the Kingdom.
16. Contact
Security: it@mahsumaah.sa · General: info@mahsumaah.sa
Mahsumah Company / شركة محسومة — Riyadh, Saudi Arabia. CR 7038325788 · VAT 312062837400003.
Legal, privacy, SLA, and compliance materials on this site are operational drafts and should be reviewed by qualified Saudi legal counsel before being used as binding contractual terms.