Mubadara.ai

Trust & Security

Built so you can answer for it

Your firm answers to clients and regulators. Mubadara.ai is designed so that every one of those answers is easy to give — with the evidence attached.

Where AI stops and rules begin

The four verbs draw a hard line through the platform. Everything on the AI side is a labelled draft; everything that counts is deterministic and signed.

What AI does

  • Reads documents, extracts fields and suggests journals — with confidence scores, for a person to accept
  • Retrieves regulation and drafts narratives, memos and client communications — with citations
  • Explains rule verdicts and risk flags in plain language

What AI never does

  • Produce a final number — tax, balances, ZATCA checks and IFRS figures come from the deterministic rules engine
  • Post, finalise or submit anything — a person reviews and signs at every gate
  • Touch your database or files directly — it reads and suggests through a controlled gateway only

Isolation & access

Isolated per firm

Each firm runs in its own tenant; cross-tenant access is denied by default. Your client data is never shared with — or visible to — another firm.

Per-firm encryption keys

Each firm's data is encrypted with its own keys — including its ZATCA certificates — so isolation holds at the storage layer, not just the application layer.

Role-based access

Access is scoped by role, engagement and period — people see what their work requires, nothing more.

Ethical walls

Independence and conflict data walls keep client teams separated by access control, not by memo.

Append-only audit trail

Who did what, when, and with which rule and model version — recorded in a trail that can be added to but never edited.

Users & Audit screen: tenant roles and the append-only audit trail
Users & Audit — partner-only roles, append-only trail. Demo tenant, fictional data.

Data residency & the cross-border gate

Structured business data — ledgers, documents and the audit trail — stays in the Kingdom (Riyadh, me-central-1). During the pilot, limited text may be sent to AI models in a nearby region; before anything leaves, a cross-border gate classifies the data, strips or pseudonymises personal information, and logs the event. Sensitive items never leave. Aligned with PDPL and SDAIA cross-border rules — consent, standard contractual clauses and a risk assessment.

The cross-border gate, level by level
ClassExampleCrosses the border?
L1 — PublicRegulations, IFRS templates, FAQsYes
L2 — Business, non-personalMasked account and amount structureOnly when masked
L3 — Personal data (PII)Client contacts, UBO, ID documentsStripped / pseudonymised + SCC
L4 — SecretsZATCA keys, bank details, disputed tax positionsNever — stays in-Kingdom

Compliance, built in

Five frameworks your firm gets asked about, and what the platform does for each.

ZATCA e-invoicing
Invoices rules-checked before submission (sandbox during the pilot) — exact error codes, field by field, with no live submission made on your behalf.
IFRS
Full statements, notes and reconciliations, computed by rules — with partner sign-off gated on every check.
Zakat · VAT · WHT
Deterministic, versioned and cited tax calculations — the model never computes the tax.
PDPL
In-Kingdom residency, consent, and a cross-border gate that classifies and de-identifies anything before it moves.
SOCPA practice
Partner sign-off and an audit trail for every engagement — working papers as a by-product, not an afterthought.

Your IT team has more questions? Good.

We'd rather answer them before the pilot than during it. Send them our way, or start with the FAQ.

Bring Mubadara.ai to your firm

Run a four-week pilot on one client — free for founding firms, hands-on from day one.