SOSME

SOSME Trust Center

LEGAL

SOSME TRUST CENTER

A centralized reference for SOSME's legal, privacy, security, compliance, and data governance framework.

SOSME is designed for enterprise and public-sector environments where security, auditability, regulatory compliance, and operational control are mandatory requirements.

This Trust Center defines how SOSME operates as a platform, how data is processed, and how responsibilities are shared between SOSME and its customers.

01

1. TERMS OF SERVICE

SOSME provides an Al-native enterprise operating system that enables organizations to manage execution, control, and intelligence across business
functions including finance, operations, HR, supply chain, compliance, and governance.

By accessing or using SOSME, the customer agrees that:

  • SOSME is a software platform and does not act as a legal, financial, or vregulatory authority
  • The customer is solely responsible for ensuring lawful use of the platform within applicable jurisdictions
  • Outputs generated by YARA Al are decision-support outputs and must be reviewed and validated before execution in regulated workflows
  • SOSME may evolve, update, or modify functionality as part of continuous product improvement
  • Access may be governed by a commercial agreement, order form, or enterprise contract, where applicable

SOSME is responsible for platform availability, infrastructure security, and system integrity.

The customer is responsible for internal governance, user access management, and operational decision- making.

02

2. PRIVACY & DATA GOVERNANCE

SOSME is designed with enterprise-grade data governance principles to ensure secure, controlled and traceable handling of customer information.

2.1 Data Ownership

Customers retain full ownership of all business data entered into SOSME.

SOSME does not sell, monetize, or trade customer data.

2.2 Data Usage

Customer data is processed strictly for:

  • Execution of business workflows
  • System automation through YARA AI
  • Operational analytics and reporting
  • Cross-module system functionality
  • Compliance, audit, and governance workflows (where enabled)

2.3 Data Processing Model

SOSME operates a controlled multi-tenant architecture:

  • Logical isolation between customer environments
  • Role-based access control (RBAC) enforced at all layers
  • Full audit logging of system activity
  • Traceable data access and system actions

2.4 Privacy Compliance

SOSME aligns its privacy framework with applicable regulations, which may include:

  • Saudi Arabian data protection requirements (where applicable)
  • GCC regulatory frameworks (where applicable)
  • GDPR-aligned privacy principles (where applicable)

Actual compliance obligations depend on customer jurisdiction and deployment configuration.

03

3. SECURITY FRAMEWORK

SOSME is built on a security-first architecture designed for enterprise and regulated environments.

3.1 SECURITY CONTROLS

  • Encryption of data in transit and at rest
  • Role-based access control (RBAC)
  • Multi-factor authentication (MFA)
  • Multi-tenant data isolation
  • Secure API authentication and authorization
  • Session security and token-based access control

3.2 MONITORING & DETECTION

  • Continuous infrastructure and application monitoring
  • Audit logging of all critical system events
  • Security event detection and alerting
  • Incident response workflows and escalation procedures

3.3 SECURE DEVELOPMENT LIFECYCLE

  • Secure-by-design engineering practices
  • Regular vulnerability scanning and remediation
  • Dependency and supply-chain security monitoring
  • Controlled release and deployment management

3.4 SHARED RESPONSIBILITY MODEL

SOSME is responsible for:

  • Platform security
  • Infrastructure protection
  • Application-level security controls

Customers are responsible for:

  • User access management
  • Credential protection
  • Internal security policies and governance enforcement

04

4. DATA RESIDENCY & HOSTING

4.1 Deployment Models

SOSME supports:

  • Cloud-hosted deployment
  • Region-specific hosting
  • Dedicated or enterprise-controlled environments (upon request)

4.2 Data Residency

Customer data may be stored in specific geographic regions based on:

  • Regulatory requirements
  • Industry compliance obligations
  • Customer contractual preferences
  • Performance and latency considerations

For Saudi Arabia and GCC customers, in-country hosting can be supported where required.

4.3 Cross-Border Transfers

Where data transfer across jurisdictions occurs, SOSME applies:

  • Encryption in transit
  • Contractual safeguards
  • Access control restrictions
  • Compliance-aligned transfer mechanisms

05

5. COMPLIANCE & GOVERNANCE

SOSME is designed for organizations operating under structured regulatory requirements, including financial,
workforce, tax, audit, and operational compliance.

5.1 Built-In Compliance
Capabilities

  • Audit trails for all operational activity
  • Workflow-based approvals and governance
  • Policy enforcement through system configuration
  • Structured documentation and record retention
  • Regulatory reporting support (where configured)

5.2 Governance Model

  • Hierarchical approval
    structures
  • Controlled workflow
    execution
  • Traceable operational
    decision flows
  • Centralized policy
    enforcement

5.3 Audit Readiness

SOSME supports audit and
regulatory review through:

  • Historical activity logs
  • Structured data traceability
  • Documented workflow
    histories
  • Exportable compliance
    reports

06

6. SERVICE LEVEL AGREEMENT (SLA)

6.1 Availability

SOSME is designed for enterprise availability targets of:

Actual uptime may vary based on:

  • Customer deployment architecture
  • Integration dependencies
  • Third-party infrastructure components

6.2 Support Models

Standard Support

  • • Business hours coverage
  • • Ticket-based support
  • • Standard response workflows

Enterprise Support

  • • Priority incident handling
  • • Dedicated escalation channels
  • Defined SLA response
  • commitments

Mission-Critical Support
(optional)

  • • 24/7 coverage
  • • Dedicated technical resources
  • • Critical incident escalation path

6.3 Incident Response (Indicative)

Critical:

Immediate prioritization

High:

Same-day response target

Medium:

Scheduled resolution cycle

Low:

Standard queue processing

Final SLAs are defined contractually.

07

7. BUSINESS CONTINUITY & RELIABILITY

SOSME maintains operational resilience through:

  • Redundant infrastructure design
  • Automated backup systems
  • Disaster recovery procedures
  • Failover and restoration mechanisms (where applicable)

Recovery objectives are defined per deployment and contract.

08

8. CUSTOMER RIGHTS

Customers retain the right to:

Access their data

Export their data

Request deletion (subject to legal/regulatory obligations)

Define retention policies (where supported)

Manage users, roles, and permissions

09

9. SUBPROCESSORS & THIRD PARTIES

SOSME may engage third-party providers for infrastructure, hosting, monitoring, and operational services.

All sub processors are selected based on:

  • Enterprise security standards
  • Compliance alignment
  • Operational reliability
  • Regional availability requirements

Detailed subprocess listings are available upon enterprise request or contractual agreement.

10

10. SECURITY & COMPLIANCE ALIGNMENT

SOSME is designed to align with globally recognized security frameworks, including:

  • ISO 27001 principles
  • (information security management)
  • SOC 2 Type II control objectives
  • (security, availability, confidentiality)
  • GDPR-aligned privacy principles
  • (where applicable)
  • Regional compliance frameworks
  • (Saudi Arabia / GCC jurisdictions)

Certification status may vary based on deployment phase and organizational rollout.

FINAL STATEMENT

SOSME is built as an enterprise operating system where:

Execution is governed

Intelligence is traceable

Data is protected

Compliance is embedded

Operations are auditable

This Trust Center forms the legal and operational
foundation for SOSME deployments across enterprise
and regulated environments.