Where data sits, per configuration
Licensing is checked against a signed file held on the deployment, so no configuration depends on a live connection to keep answering calls. See Licensing and egress.
Residency selection between Saudi Arabia and the EU, private deployment, and a self-hosted control plane are enterprise-tier options. They are scoped per engagement rather than switched on in a console.
Sovereignty is more than location
A deployment can sit physically in Riyadh and still fail a sovereignty review. The questions that actually get asked:Who can technically access it?
Who can technically access it?
Not who is contractually permitted to, but who holds credentials that would work. In a self-hosted deployment, that is your directory and nobody else’s.
What egress exists at all?
What egress exists at all?
A security review will scan for it rather than take the answer on trust. In a self-hosted deployment the answer is the periodic usage sync for billing, and nothing else. See Licensing and egress.
Where do the models come from, and how are they updated?
Where do the models come from, and how are they updated?
Update media, how it is delivered, and who can trigger an update in your environment.
Is call data used for training?
Is call data used for training?
Ask it explicitly, ask whether it can be switched off, and get the answer in the contract rather than in a slide.
What happens when the contract ends?
What happens when the contract ends?
In a self-hosted deployment the data is already yours and stays where it is. Confirm what happens to the software.
PDPL and the Gulf
Saudi Arabia’s Personal Data Protection Law places specific requirements on processing personal data, including rules on transfers outside the Kingdom. Comparable regimes apply across the Gulf. Call audio is personal data in its own right in most jurisdictions, and biometric data in some. Where an obligation restricts transfers outside the country, a deployment that processes calls inside your own environment removes the transfer from the picture rather than justifying it. That is the argument on-premise is usually bought for, but it is your legal team’s argument to make, against your obligations.Evidence your reviewers will ask for
Have these ready before the security review rather than during it:- A network diagram showing the boundary and every path that crosses it. See Architecture.
- The egress answer for your mode, and how it is enforced.
- Retention periods per data type: audio, transcripts, summaries, action logs.
- The access model: who can read transcripts, under which role, through which identity provider.
- The audit trail and where it is streamed.
- The deletion procedure, tested.
- The caller notification your line plays, and when in the call it plays.
Related
Security and data handling
What a voice line collects, and what to settle before launch.
Architecture
The boundary, drawn.

