Security

Your data. Your machine. Your country.

Every security claim on this page is a contract line, not a marketing line. Built for manufacturers who handle proprietary formulations, trade secrets, and regulated industrial data.

Dana AI data sovereignty — air-gapped server room with biometric cabinets, UAE flag, and security officer reviewing access logs
FIVE SECURITY CLAIMS

Five claims. Each a contract line.

1. Tenant isolation

Every customer runs in their own dedicated tenancy — their own VPC, private cloud, or on-prem environment. No shared inference layer. No shared vector store. No cross-customer data paths.

2. Data residency

Inference, telemetry, and audit logs all stay inside the jurisdictional boundary you specify — UAE, Saudi Arabia, Qatar, Bahrain, Oman, or Kuwait. No data flows through a foreign region. Not for model improvement. Not for debugging. Compliant with CBUAE, ADGM/DIFC, NDMO/PDPL, and SDAIA.

3. Full audit logging

Every agent action is logged with SSO identity, timestamp, input, output, and the policy that governed the decision. Queryable. Exportable. ISO-ready.

4. Local inference

Model weights and the reasoning runtime sit on infrastructure you own. Reasoning does not egress. Telemetry does not egress.

5. In-house development

The platform is built and extended by Dure and AILab engineers. No third-party black boxes in the critical path. Source available under enterprise licence.

Dana AI five security layers — isolation, residency, audit, local inference, in-house
GCC REGULATORY COMPLIANCE

Compliant by architecture, not by attestation.

CBUAE
SAMA
ADGM
DIFC
PDPL
UCP 600

Certifications

SOC 2 Type II

Readiness · Q3 2026

ISO 27001

In assessment

Security brief

Full brief available under NDA via security@danagroups.com

Dana AI GCC compliance matrix — five security claims mapped to CBUAE, PDPL, SDAIA, ADGM, DIFC and SOC 2 ISO 27001

Where to go next

EXPLORE

Security — Sovereign by Design

Dana AI Security mind map -- five security claims with GCC regulatory framework mapping

Need the full security brief?

Available under NDA. Email security@danagroups.com or book a working session.

Contact Us →
FAQ

Frequently Asked Questions

Where does Dana AI data reside?

All data — inference, telemetry, audit logs — remains inside the customer's jurisdictional boundary. UAE, Saudi Arabia, Qatar, Bahrain, Oman, or Kuwait. No data flows through a foreign region.

Is Dana AI SOC 2 and ISO 27001 certified?

SOC 2 Type II readiness targeted for Q3 2026. ISO 27001 in assessment. Full security brief available under NDA via security@danagroups.com.

Does Dana AI use third-party AI services?

No. The platform is built and extended by Dure and AILab engineers. Model weights sit on customer infrastructure. No third-party black boxes in the critical path.

ABOUT DANA AI

Dana AI by Dana Groups — Sovereign Industrial AI for the GCC

Dana AI is the artificial intelligence division of Dana Groups, a UAE-based industrial conglomerate with heritage dating to 1991. The current holding structure has operated since 2009 across eight companies in steel manufacturing, oil and gas services, industrial equipment, water heating systems, and commodity trading. The Dana AI platform is sovereign by architecture — tenant-isolated, in-country, fully audit-logged, locally inferenced, and built and extended in-house by Dure Technologies and AILab. Deployments are compliant with the UAE National AI Strategy 2031, CBUAE Cloud Computing Regulation, ADGM and DIFC data protection, Saudi NDMO/PDPL, SDAIA AI Ethics Framework, Qatar NDPL, Bahrain PDPL, Oman PDPL, and Kuwait DPPR, with SOC 2 Type II readiness in Q3 2026 and ISO 27001 in assessment. Dana AI is not affiliated with Dana Incorporated (NYSE: DAN), Dana Air, or any other entity using the Dana name.

GET STARTED

Book a Working Session

Forty-five minutes with an operator who has deployed this inside a real manufacturing business. You leave with the workflow we would automate first.

Or email us → hello@danagroups.com  |  Call: +971-4-2217273

Translate »