Every modern application needs the same six things behind it. A database, an API over that database, user authentication, file storage, live updates and somewhere to run server side code. Foreign platforms provide all six in an afternoon, and no regulated Saudi organisation can use them for data that has to stay here. SilentSpace is those six services, installed on your own hardware, administered from one screen in Arabic or English.
Most vendors answer the residency question with a data centre location and ask you to accept it. This one is answered by your own hardware, in front of you, in about a minute.
SilentSpace ships with an evaluation you run on your own servers. It walks into each component's own network namespace and asks the kernel to list every connection that component is holding. On a reference install the answer is ten components, forty eight network peers, and none of them outside the local network.
That is not a statement by the vendor about the vendor's product. It is your kernel, on your hardware, reporting on software you control, and your own engineers can reproduce it without believing anybody. There is no telemetry, no phone home, no content delivery network, no web font and no update channel, which is why it installs inside networks with no route to the internet at all.
The report it produces states what it cannot prove as plainly as what it can, including the gaps that remain open. An auditor forgives a stated gap and never forgives a discovered one.
“in principle only cloud services should be used that are located in Saudi Arabia, or when cloud services are to be used outside Saudi Arabia that the Member Organization should obtain explicit approval from SAMA”, and “the Member Organization should obtain SAMA approval prior to using cloud services or signing the contract with the cloud provider”. The same section states: “Please note that this requirement is not applicable to private cloud services (= internal cloud).”
We quote that carve-out ourselves because your compliance team will find it. Section 3.4.3 shapes how a regulated institution builds rather than compelling this particular purchase, and SilentSpace deploys inside your own environment, which is the private cloud the carve-out describes. What it buys you is not an exemption. It is a deployment where the residency question stops being a contractual promise and becomes something you can measure.
Your team writes the application. Everything behind it arrives already built, already secured and already documented.
PostgreSQL, with a REST and GraphQL API generated from your own tables that reloads the moment the schema changes. No endpoint is hand written and none can drift from the data it serves.
A database event trigger enables row level security on every table the moment it is created. A table with no policy returns nothing to an anonymous caller. Every platform assembled from these components defaults the other way, which is why anonymous key data exposures reach the news several times a year.
Every change to the shape of your data is recorded without anyone remembering to record it. Update and delete are rejected for every role including the administrator, and each entry carries the hash of the entry before it, so any forced alteration is detectable.
The drill restores a backup into an isolated copy beside the live system, compares the contents, confirms the audit chain still verifies inside the restored copy, and writes its own verdict into the audit trail with a date on it. Production is never touched.
The whole platform is a 1.5 GB bundle that fits on any approved USB device. The installer verifies it against its checksums, loads the images from the file, generates every credential on your machine and runs the acceptance test in front of you.
The administration screen runs in Arabic with a genuinely mirrored right to left layout, not translated labels on a left to right page. Your own staff administer it in their own language.
Twenty-one controls in scope, mapped one by one against the NCA Cloud Cybersecurity Controls and the SAMA Cyber Security Framework. The full mapping goes to a buyer before the commercial conversation, not after it.
We do not claim full compliance and no vendor can. Compliance is a property of a deployment and of the organisation operating it, assessed by your auditor. It is not a badge that attaches to software. An auditor respects a stated gap and never forgives a surprise, so ours are written down.
Every figure below was produced by running the software, and each one is reproducible by your own team on a pilot server.
What would your auditor need to see before you could run this in production? Tell us that, and we will show you whether SilentSpace answers it. If it does not, we will say so in the room rather than in month six. We are not taking payment for any of it yet, and nothing is invoiced before our company registration is complete, so the answer to that question costs you nothing.