SOSME Trust Center
LEGAL
SOSME TRUST CENTER
A centralized reference for SOSME's legal, privacy, security, compliance, and data governance framework.
SOSME is designed for enterprise and public-sector environments where security, auditability, regulatory compliance, and operational control are mandatory requirements.
This Trust Center defines how SOSME operates as a platform, how data is processed, and how responsibilities are shared between SOSME and its customers.
01
1. TERMS OF SERVICE
SOSME provides an Al-native enterprise operating system that enables organizations to manage execution, control, and intelligence across business
functions including finance, operations, HR, supply chain, compliance, and governance.
By accessing or using SOSME, the customer agrees that:
- SOSME is a software platform and does not act as a legal, financial, or vregulatory authority
- The customer is solely responsible for ensuring lawful use of the platform within applicable jurisdictions
- Outputs generated by YARA Al are decision-support outputs and must be reviewed and validated before execution in regulated workflows
- SOSME may evolve, update, or modify functionality as part of continuous product improvement
- Access may be governed by a commercial agreement, order form, or enterprise contract, where applicable
SOSME is responsible for platform availability, infrastructure security, and system integrity.
The customer is responsible for internal governance, user access management, and operational decision- making.
02
2. PRIVACY & DATA GOVERNANCE
SOSME is designed with enterprise-grade data governance principles to ensure secure, controlled and traceable handling of customer information.
2.1 Data Ownership
Customers retain full ownership of all business data entered into SOSME.
SOSME does not sell, monetize, or trade customer data.
2.2 Data Usage
Customer data is processed strictly for:
- Execution of business workflows
- System automation through YARA AI
- Operational analytics and reporting
- Cross-module system functionality
- Compliance, audit, and governance workflows (where enabled)
2.3 Data Processing Model
SOSME operates a controlled multi-tenant architecture:
- Logical isolation between customer environments
- Role-based access control (RBAC) enforced at all layers
- Full audit logging of system activity
- Traceable data access and system actions
2.4 Privacy Compliance
SOSME aligns its privacy framework with applicable regulations, which may include:
- Saudi Arabian data protection requirements (where applicable)
- GCC regulatory frameworks (where applicable)
- GDPR-aligned privacy principles (where applicable)
Actual compliance obligations depend on customer jurisdiction and deployment configuration.
03
3. SECURITY FRAMEWORK
SOSME is built on a security-first architecture designed for enterprise and regulated environments.
3.1 SECURITY CONTROLS
- Encryption of data in transit and at rest
- Role-based access control (RBAC)
- Multi-factor authentication (MFA)
- Multi-tenant data isolation
- Secure API authentication and authorization
- Session security and token-based access control
3.2 MONITORING & DETECTION
- Continuous infrastructure and application monitoring
- Audit logging of all critical system events
- Security event detection and alerting
- Incident response workflows and escalation procedures
3.3 SECURE DEVELOPMENT LIFECYCLE
- Secure-by-design engineering practices
- Regular vulnerability scanning and remediation
- Dependency and supply-chain security monitoring
- Controlled release and deployment management
3.4 SHARED RESPONSIBILITY MODEL
SOSME is responsible for:
- Platform security
- Infrastructure protection
- Application-level security controls
Customers are responsible for:
- User access management
- Credential protection
- Internal security policies and governance enforcement
04
4. DATA RESIDENCY & HOSTING
4.1 Deployment Models
SOSME supports:
- Cloud-hosted deployment
- Region-specific hosting
- Dedicated or enterprise-controlled environments (upon request)
4.2 Data Residency
Customer data may be stored in specific geographic regions based on:
- Regulatory requirements
- Industry compliance obligations
- Customer contractual preferences
- Performance and latency considerations
For Saudi Arabia and GCC customers, in-country hosting can be supported where required.
4.3 Cross-Border Transfers
Where data transfer across jurisdictions occurs, SOSME applies:
- Encryption in transit
- Contractual safeguards
- Access control restrictions
- Compliance-aligned transfer mechanisms
05
5. COMPLIANCE & GOVERNANCE
SOSME is designed for organizations operating under structured regulatory requirements, including financial,
workforce, tax, audit, and operational compliance.
5.1 Built-In Compliance
Capabilities
- Audit trails for all operational activity
- Workflow-based approvals and governance
- Policy enforcement through system configuration
- Structured documentation and record retention
- Regulatory reporting support (where configured)
5.2 Governance Model
- Hierarchical approval
structures - Controlled workflow
execution - Traceable operational
decision flows - Centralized policy
enforcement
5.3 Audit Readiness
SOSME supports audit and
regulatory review through:
- Historical activity logs
- Structured data traceability
- Documented workflow
histories - Exportable compliance
reports
06
6. SERVICE LEVEL AGREEMENT (SLA)
6.1 Availability
SOSME is designed for enterprise availability targets of:
Actual uptime may vary based on:
- Customer deployment architecture
- Integration dependencies
- Third-party infrastructure components
6.2 Support Models
Standard Support
- • Business hours coverage
- • Ticket-based support
- • Standard response workflows
Enterprise Support
- • Priority incident handling
- • Dedicated escalation channels
- Defined SLA response
- commitments
Mission-Critical Support
(optional)
- • 24/7 coverage
- • Dedicated technical resources
- • Critical incident escalation path
6.3 Incident Response (Indicative)
Critical:
Immediate prioritization
High:
Same-day response target
Medium:
Scheduled resolution cycle
Low:
Standard queue processing
Final SLAs are defined contractually.
07
7. BUSINESS CONTINUITY & RELIABILITY
SOSME maintains operational resilience through:
- Redundant infrastructure design
- Automated backup systems
- Disaster recovery procedures
- Failover and restoration mechanisms (where applicable)
Recovery objectives are defined per deployment and contract.
08
8. CUSTOMER RIGHTS
Customers retain the right to:
Access their data
Export their data
Request deletion (subject to legal/regulatory obligations)
Define retention policies (where supported)
Manage users, roles, and permissions
09
9. SUBPROCESSORS & THIRD PARTIES
SOSME may engage third-party providers for infrastructure, hosting, monitoring, and operational services.
All sub processors are selected based on:
- Enterprise security standards
- Compliance alignment
- Operational reliability
- Regional availability requirements
Detailed subprocess listings are available upon enterprise request or contractual agreement.
10
10. SECURITY & COMPLIANCE ALIGNMENT
SOSME is designed to align with globally recognized security frameworks, including:
- ISO 27001 principles
- (information security management)
- SOC 2 Type II control objectives
- (security, availability, confidentiality)
- GDPR-aligned privacy principles
- (where applicable)
- Regional compliance frameworks
- (Saudi Arabia / GCC jurisdictions)
Certification status may vary based on deployment phase and organizational rollout.
FINAL STATEMENT
SOSME is built as an enterprise operating system where:
Execution is governed
Intelligence is traceable
Data is protected
Compliance is embedded
Operations are auditable