Skip to content

Founding Partner program — now open

GRC built for the Kingdom — not translated for it.

Regulator-grade rigor, AI-native, Arabic-first. One connected system across every GRC domain — pre-mapped to the frameworks your auditors already use.

30-minute walkthrough · In Arabic or English · No commitment

01

Arabic-first, not translated

Full RTL interface, bilingual on every record, Hijri/Gregorian calendar, branded Arabic PDFs — built for Arabic teams from the ground up.

02

GCC regulations, ready on day one

NCA ECC 2.0, SAMA CSF, PDPL, NESA, ISO 27001 and more — 700+ controls pre-seeded with crosswalks. Activate a framework in one click.

03

AI embedded in every workflow

A conversational GRC Advisor plus inline AI for risk scoring, treatment, gap analysis, and evidence validation — native, not a bolt-on.

The difference

Built in-Kingdom — not localized after the fact.

Foreign GRC tools bolt on Arabic and data residency as afterthoughts. For Luftic, they are the foundation.

Data residency
LufticKSA on-prem, private cloud, or Oracle KSA Object Storage — encrypted, never leaves the jurisdiction
Foreign GRC toolsUS/EU primary; residency a paid add-on
Arabic experience
LufticArabic-first, full RTL on every record
Foreign GRC toolsEnglish-first; partial UI translation
Hijri calendar
LufticHijri + Gregorian, native side by side
Foreign GRC toolsGregorian only
GCC frameworks
LufticNCA, SAMA, PDPL, NESA pre-seeded with crosswalks
Foreign GRC toolsSOC 2 / ISO focus; GCC mapping is DIY
Deployment
LufticSelf-host or KSA private cloud
Foreign GRC toolsShared SaaS only
Evidence security
LufticEncrypted at rest, malware-scanned, tamper-evident hash-chain
Foreign GRC toolsStandard cloud storage; scanning & residency cost extra

The platform

Eight domains. One connected system.

Risk, compliance, policy, incident, audit, vendor, controls, and evidence share one data model — change something once and it propagates everywhere.

New

Risk

5×5 register with live residual scoring

Compliance

Real-time posture across every framework

New

Policy

Lifecycle, versioning & attestation campaigns

New

Incident

PDPL 72-hour breach response, built in

Audit

Internal audit & tamper-evident trail

New

Vendor

TPRM registry + token-secured vendor portal

Controls

One control, mapped across frameworks

Evidence

Upload once, comply many — OCR indexed

Capabilities

Built to retire the spreadsheet stack.

Signature capability

Upload once, comply many

One evidence file satisfies equivalent controls across NCA ECC, ISO 27001 and SAMA simultaneously via crosswalk mappings.

Signature capability

Regulatory deadline engine

A PDPL data-breach incident auto-starts the 72-hour notification timer; NCA ECC obligations track themselves.

17 modules, one platform

Risk, compliance, policy, incident, audit, vendor TPRM, controls, evidence — integrated, replacing spreadsheets and siloed tools.

Codeless workflow engine

Drag-and-drop approval chains with conditional branching, SLAs, and delegation across every module — no developers.

Vendor risk with SAMA TPRM built in

Send the pre-loaded SAMA TPRM & PDPL DPA questionnaires day one; vendors respond in a branded self-service portal — no account needed.

Tamper-evident audit trail

Every change is cryptographically hash-chained — provable to regulators and boards that records were never altered.

Third-party risk

New

Onboard vendors without the email ping-pong.

A token-secured portal lets vendors answer SAMA TPRM and PDPL DPA questionnaires directly — risk-tiered, scored, and tracked through to contracts and findings.

  • Risk-tiered vendor registry with inherent & residual scoring
  • Pre-loaded SAMA TPRM, SIG Lite & PDPL DPA questionnaires
  • Self-service vendor portal — no account, no back-and-forth
  • Contracts, findings & fourth-party tracking in one record
portal.luftic.com/vendorSAMA TPRM
Vendor risk register14 vendors
AAlmaha CloudHigh
TTatweer SystemsMedium
NNumu LogisticsLow
SAMA TPRM questionnaireAlmaha Cloud
24 / 30 answered80%

AI Advisor

An advisor that does the work — not a dashboard that reports it.

Ask in plain Arabic or English. The GRC Advisor scores risks, drafts treatments, runs gap analysis, and validates evidence inline — grounded in your frameworks and your data.

  • Maps controls across frameworks
  • Scores risks and drafts treatment plans
  • Runs compliance gap analysis
  • Validates evidence and scores completeness
  • Writes records — only on your approval
AI Advisor

Good evening 👋 Want to review what’s pending before you wrap up?

Looking good. No urgent items right now. ✨

1 risk needs assessment — want AI scoring help?
Start my day — give me a full briefing
Show me this week’s risk landscape
Which frameworks need the most attention?
How audit-ready are we right now?
Ask a question about your GRC program…

Enter to send · Shift+Enter for newline

Time to value

Live in minutes, not months.

Frameworks ship pre-seeded and dashboards come role-ready, so your program is running the day you sign in.

  1. 1

    Activate a framework in one click

    Controls and crosswalks are pre-seeded — no manual import.

  2. 2

    Resume setup anytime

    A 7-step wizard saves your draft as you go.

  3. 3

    Open role-based dashboards

    Sensible defaults are ready for each team and persona.

  4. 4

    Follow the guided tour

    Your team is productive from day one.

17

Modules

700+

Controls pre-seeded

8+

Frameworks

29+

Dashboard widgets

Under the hoodMulti-tenant isolationMFA + step-up authDynamic RBAC + SoDReal-time dashboards · 29+ widgetsPublic API & developer portalOn-prem / KSA data residency

Integrations

Connect your stack.

Pull evidence and push alerts across the tools your team already runs — with a public REST API, developer portal, and webhook platform for everything else.

Live now
AWSSlackMicrosoft TeamsSSO / SAMLWebhooksREST API
On the roadmap
Microsoft AzureMicrosoft 365GitHubJiraOkta

Book a demo

See Luftic on your frameworks — in 30 minutes.

A live walkthrough with our team, shaped around your regulators and the way you work today. No slides, no pressure.

  • Your frameworks, mapped

    NCA ECC, SAMA CSF, PDPL or NESA — activated live, with the crosswalks your auditors expect.

  • The AI Advisor at work

    Ask it about your gaps, risks and evidence — in Arabic or English.

  • A clear rollout plan

    Leave with the steps, timeline and effort it takes to go live.

  • 30 minutes
  • Arabic or English
  • No commitment

Request your demo

We reply within one business day to confirm a time that suits you.

Frameworks of interest (optional)

By submitting, you agree to our privacy notice. We use your details only to arrange your demo.

Founding Partner program

Shape the platform. Lock founding terms.

We are taking a small cohort of GRC consultancies and in-Kingdom risk teams as Founding Partners — early access, founding terms, and a direct hand in shaping the platform.

  • Shape the roadmap

    A direct line to the product team. Your frameworks and workflows get prioritized.

  • Founding pricing, locked

    Preferential terms held for the life of your contract.

  • White-glove onboarding

    Migration, framework activation, and tenant setup done with you.

  • In-Kingdom from day one

    Data residency and Arabic-first support, no compromises.

Apply to become a Founding Partner

We review every application personally. Expect a reply within two business days.

GRC, made clear.

Book a 30-minute demo, or apply to the Founding Partner program and help build the standard for compliance in the Kingdom.