Billing Automation Collections Pricing Customers Insights About

Security and Compliance

Your billing data stays in the Kingdom.

Stream is built for PDPL compliance from the ground up. Data residency in KSA, end-to-end encryption on every transmission, and a security posture aligned with the regulatory context your organisation operates in.

KSA
Data residency region
TLS 1.3
Encryption in transit
AES-256
Encryption at rest

Data Protection

PDPL compliance built into the platform

Data Residency

All personal data processed by Stream, including billing contacts, invoice records, and communication logs, is stored in KSA-region infrastructure. Data does not leave the Kingdom without your explicit written consent. This satisfies PDPL requirements on cross-border data transfers applicable to organisations processing personal data in Saudi Arabia.

Encryption

All data in transit between Stream and your clients is encrypted using TLS 1.3. All data at rest is encrypted using AES-256. This applies to invoice content, payment records, contact information, and communication history. Encryption keys are managed in a dedicated key management service with access audit logging.

Access Control

Role-based access controls let you determine which team members can see billing data, run collection sequences, or change account configurations. Every action is logged with a timestamp and user identity. Audit logs are retained for 12 months and are available for export on request.

Data Processor Agreement

Stream acts as a data processor under your organisation's data controller obligations. We provide a standard Data Processor Agreement for all customers. The agreement covers processing purpose limitation, sub-processor disclosure, data subject rights support, and breach notification timelines consistent with PDPL requirements.

Compliance

Regulatory standards we align with

PDPL

Personal Data Protection Law (Saudi Arabia). Data residency, consent management, cross-border transfer restrictions, and data subject rights are all addressed in Stream's platform design and contractual commitments.

ZATCA E-Invoicing

Stream generates invoices in ZATCA-compliant e-invoicing format for organisations subject to Saudi tax authority requirements. Phase 1 and Phase 2 e-invoicing workflows are supported.

NCA Compliance

Stream's infrastructure configuration is aligned with the National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC) applicable to cloud-hosted services processing personal data in Saudi Arabia.

SOC 2 Alignment

Stream's security controls are aligned with SOC 2 Type II criteria covering availability, confidentiality, and security. We are currently in the process of completing formal third-party attestation. Security review documentation is available under NDA to Enterprise customers.

Penetration Testing

Stream engages a third-party security firm to conduct annual penetration tests of the platform's application and infrastructure layers. Critical findings are remediated within 30 days. Test summaries are available to Enterprise customers.

Incident Response

Stream maintains a documented incident response plan with defined escalation paths and customer notification timelines. In the event of a security incident affecting your data, we notify affected customers within 72 hours of confirmed discovery.

Infrastructure

How we run Stream reliably and securely

KSA-region cloud infrastructure

All compute, storage, and database resources are provisioned in a Saudi Arabia cloud region. We do not use foreign data centres for any primary data processing.

Automated backups and point-in-time recovery

All billing data is backed up daily with point-in-time recovery available. Retention period is 90 days. Recovery objectives are tested quarterly.

99.9% uptime SLA

Stream targets 99.9% monthly uptime for all API and application endpoints. Planned maintenance windows are announced at least 48 hours in advance. Status updates are published at status.gostreampay.com.

Network isolation and VPC segmentation

Production workloads run in an isolated VPC with strict inbound/outbound rules. Database and processing layers are not publicly accessible. All external access goes through authenticated, rate-limited API gateways.

Security questions? We are glad to walk you through it.

Our team can provide detailed security documentation, DPA templates, and a technical review for procurement and compliance teams.