Skip to main content
Back to Home

Trust & Compliance

At ENTEK.AI, we maintain the highest standards of compliance and security in energy trading. Our platform is built on a foundation of trust, transparency, and regulatory adherence.

UN Environment Recognition

ENTEK.AI is proud to be recognized by the United Nations Environment Programme for our innovative approach and commitment to sustainable energy solutions in the MENA region. This recognition validates our dedication to environmental stewardship and our role as pioneers in green energy transformation.

Innovation in Sustainable Energy Management
Commitment to Environmental Protection and Carbon Reduction
Regional Leadership in Green Energy Solutions
Supporting UN Sustainable Development Goals
UN Environment Certificate presented to ENTEK.AI

International Standards & Certifications

We are committed to achieving and maintaining the highest industry standards

Coming Soon

ISO 27001

Information Security Management

Our marketplace platform handles sensitive energy trading data. ISO 27001 certification will ensure we maintain world-class information security controls to protect your business data and transactions.

  • Secure data encryption and storage
  • Regular security audits and risk assessments
  • Continuous monitoring and incident response
Coming Soon

ISO 9001

Quality Management Systems

Ensuring consistent quality in our marketplace operations, supplier verification processes, and customer service delivery through internationally recognized quality management standards.

  • Rigorous supplier vetting and quality assurance
  • Continuous process improvement and optimization
  • Customer satisfaction measurement and feedback
Coming Soon

ISO 50001

Energy Management Systems

As an energy marketplace and management platform, ISO 50001 certification will demonstrate our commitment to optimizing energy performance and promoting sustainable energy practices.

  • Energy performance monitoring and optimization
  • Systematic approach to energy efficiency improvements
  • Reduction of energy costs and environmental impact
Coming Soon

ISO 14001

Environmental Management Systems

Aligning with our UN recognition, ISO 14001 will formalize our commitment to minimizing environmental impact and promoting sustainable practices across our energy marketplace operations.

  • Environmental impact assessment and reduction
  • Compliance with environmental regulations
  • Sustainable resource management and waste reduction

Our Commitment to Compliance

At ENTEK.AI, we understand that trust is the foundation of successful energy partnerships. Our commitment to achieving these international certifications reflects our dedication to operational excellence, data security, and environmental responsibility.

We are actively working towards obtaining these certifications and will update our compliance status as we progress. For specific questions about our compliance standards, security measures, or certification timeline, please contact our compliance team at [email protected].

Compliance Legal Documentation

The following legal content is included in a terms-like document format.

Compliance Documentation for ENTEK.AI

Last Updated: November 12, 2025

 

1. Executive Summary

ENTEK.AI is committed to maintaining the highest standards of legal, regulatory, and ethical compliance in all aspects of our operations. As an AI-powered energy marketplace operating in the Kingdom of Saudi Arabia and serving customers across the MENA region, we adhere to comprehensive compliance frameworks covering data protection, energy sector regulations, financial services, cybersecurity, and environmental sustainability.

 

This Compliance Documentation outlines our commitment to regulatory adherence and describes the frameworks, policies, and procedures we have implemented to ensure ongoing compliance with all applicable laws and regulations.

 

2. Regulatory Framework Overview

ENTEK.AI operates under a complex regulatory environment that includes:

 

2.1 Data Protection and Privacy

Saudi Personal Data Protection Law (PDPL)

 

The PDPL, which came into force on September 14, 2023, governs the collection, processing, storage, and transfer of personal data in Saudi Arabia. ENTEK.AI is fully compliant with all PDPL requirements, including:

 

Lawful processing of personal data based on consent, contractual necessity, legal obligation, or legitimate interests

Implementation of appropriate technical and organizational security measures

Appointment of a Data Protection Officer (DPO)

Data breach notification procedures (within 72 hours to SDAIA)

Respect for data subject rights (access, rectification, erasure, portability, objection)

Cross-border data transfer safeguards using Standard Contractual Clauses and Transfer Risk Assessments

Maintenance of comprehensive data processing records

 

Regulatory Authority: Saudi Data and Artificial Intelligence Authority (SDAIA)

 

Compliance Status: Fully compliant since September 14, 2024

 

2.2 Energy Sector Regulations

Saudi Electricity Regulatory Authority (SERA)

 

SERA regulates the electricity and energy sector in Saudi Arabia to ensure reliability, safety, and efficiency of energy supply.

 

Key Regulations:

 

Law on Dry Gas and Liquified Petroleum Gas (LPG) Distribution (Royal Decree M/112): Governs the licensing, distribution, and safety standards for LPG and dry gas distribution for residential and commercial purposes

Technical Regulation for Tanks – Part 2: LPG Tankers: Establishes safety standards for LPG transport vehicles and equipment

Energy Efficiency Standards: Requirements for monitoring, reporting, and improving energy efficiency

 

Compliance Measures:

 

All suppliers on our platform are verified to hold valid energy distribution licenses

Regular audits of supplier compliance with safety and quality standards

Adherence to SASO (Saudi Standards, Metrology and Quality Organization) standards for equipment and vehicles

Implementation of safety training programs for delivery personnel

Emergency response protocols and incident reporting systems

 

Compliance Status: Fully compliant with all energy sector regulations

 

2.3 Financial Services and Payment Processing

Saudi Central Bank (SAMA) Regulations

 

As a platform that facilitates financial transactions, ENTEK.AI complies with SAMA regulations governing payment processing, anti-money laundering (AML), and counter-terrorism financing (CTF).

 

Key Compliance Areas:

 

Payment Services Provider Regulations: Compliance with rules governing electronic payment processing

Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF): Implementation of Know Your Customer (KYC) procedures, transaction monitoring, and suspicious activity reporting

Consumer Protection: Fair pricing, transparent terms, and dispute resolution mechanisms

Data Security: PCI-DSS compliance for payment card data handling

 

Compliance Measures:

 

Partnership with licensed payment service providers (PSPs)

KYC verification for all corporate clients and suppliers

Automated transaction monitoring for suspicious activities

Regular AML/CTF training for relevant staff

Secure payment processing infrastructure with end-to-end encryption

 

Compliance Status: Fully compliant with SAMA regulations

 

2.4 Cybersecurity

National Cybersecurity Authority (NCA) Requirements

 

The NCA establishes cybersecurity standards for critical infrastructure and essential services in Saudi Arabia.

 

Key Frameworks:

 

Essential Cybersecurity Controls (ECC): Mandatory controls for organizations operating critical infrastructure

Cybersecurity Regulatory Framework: Requirements for risk management, incident response, and business continuity

Data Classification and Protection Standards: Guidelines for protecting sensitive information

 

Compliance Measures:

 

Implementation of comprehensive cybersecurity controls aligned with NCA ECC framework

Regular vulnerability assessments and penetration testing

24/7 security operations center (SOC) for threat detection and response

Incident response plan with notification procedures to NCA

Employee cybersecurity awareness training

Third-party security assessments for all service providers

Business continuity and disaster recovery plans

 

Compliance Status: Fully compliant with NCA cybersecurity requirements

 

2.5 Taxation

General Authority of Zakat and Tax (GAZT)

 

ENTEK.AI complies with all tax obligations in Saudi Arabia, including:

 

Value Added Tax (VAT): 15% VAT on applicable transactions

Corporate Income Tax: Compliance with corporate tax filing and payment obligations

Withholding Tax: Proper withholding and remittance for cross-border payments

 

Compliance Measures:

 

VAT registration and regular filing of VAT returns

Accurate invoicing with VAT details

Maintenance of comprehensive financial records

Engagement of qualified tax advisors

Regular tax audits and assessments

 

Compliance Status: Fully compliant with all tax obligations

 

2.6 Environmental Compliance and Sustainability

Saudi Vision 2030 and ESG Standards

 

ENTEK.AI is committed to supporting Saudi Vision 2030's sustainability goals and maintaining high Environmental, Social, and Governance (ESG) standards.

 

Compliance Areas:

 

Carbon Emissions Tracking: Real-time monitoring and reporting of carbon footprint

Carbon Offset Programs: Verified carbon credit programs for clients

Renewable Energy Promotion: Facilitating access to renewable energy sources

Environmental Impact Assessments: Regular assessments of environmental impact

Sustainable Operations: Energy-efficient infrastructure and green logistics

 

Recognition:

 

UN Environment Programme recognition for sustainable energy solutions

Alignment with UN Sustainable Development Goals (SDGs)

 

Compliance Status: Active ESG program with ongoing improvements

 

3. Compliance Management System

3.1 Governance Structure

Board of Directors

 

The Board provides oversight of compliance matters and approves major compliance policies and initiatives.

 

Chief Compliance Officer (CCO)

 

The CCO is responsible for developing, implementing, and monitoring the compliance program across all business units.

 

Compliance Committee

 

A cross-functional committee that meets quarterly to review compliance matters, assess risks, and recommend policy updates.

 

Data Protection Officer (DPO)

 

The DPO oversees all data protection and privacy compliance matters, serves as the point of contact for SDAIA, and manages data subject requests.

 

Department Compliance Champions

 

Each department has designated compliance champions who ensure day-to-day adherence to compliance policies and procedures.

 

3.2 Compliance Policies and Procedures

ENTEK.AI has implemented comprehensive policies covering:

 

Data Protection and Privacy Policy

Information Security Policy

Anti-Money Laundering and Counter-Terrorism Financing Policy

Code of Conduct and Ethics

Supplier Verification and Due Diligence Procedures

Incident Response and Breach Notification Procedures

Records Retention and Destruction Policy

Third-Party Risk Management Policy

Whistleblower Protection Policy

Conflict of Interest Policy

 

All policies are reviewed annually and updated as needed to reflect regulatory changes.

 

3.3 Risk Assessment and Management

Annual Compliance Risk Assessment

 

We conduct comprehensive annual risk assessments to identify, evaluate, and prioritize compliance risks across all areas of operation.

 

Risk Mitigation Strategies

 

For each identified risk, we develop and implement mitigation strategies, including:

 

Enhanced controls and monitoring

Staff training and awareness programs

Technology solutions and automation

Third-party audits and assessments

Insurance coverage

 

Ongoing Risk Monitoring

 

We continuously monitor compliance risks through:

 

Key risk indicators (KRIs) and metrics

Regular internal audits

Compliance testing and validation

Incident tracking and analysis

Regulatory updates monitoring

 

3.4 Training and Awareness

Mandatory Compliance Training

 

All employees complete mandatory compliance training upon joining and annually thereafter, covering:

 

Data protection and privacy (PDPL compliance)

Information security and cybersecurity

Anti-money laundering and fraud prevention

Code of conduct and ethics

Sector-specific regulations (energy, financial services)

 

Role-Specific Training

 

Employees in specific roles receive additional specialized training relevant to their responsibilities.

 

Awareness Campaigns

 

Regular communications, newsletters, and campaigns to maintain high levels of compliance awareness throughout the organization.

 

3.5 Monitoring and Auditing

Internal Audits

 

Our internal audit function conducts regular audits of compliance with policies, procedures, and regulatory requirements.

 

External Audits

 

We engage independent third-party auditors to conduct annual compliance audits and certifications, including:

 

ISO 27001 (Information Security Management)

ISO 9001 (Quality Management)

PCI-DSS (Payment Card Industry Data Security Standard)

SOC 2 Type II (Service Organization Controls)

 

Regulatory Inspections

 

We cooperate fully with regulatory inspections and examinations by SDAIA, SERA, SAMA, NCA, and other authorities.

 

Continuous Monitoring

 

Automated monitoring systems track compliance metrics, detect anomalies, and generate alerts for potential compliance issues.

 

3.6 Incident Management and Reporting

Incident Response Plan

 

We maintain a comprehensive incident response plan covering:

 

Data breaches and privacy incidents

Cybersecurity incidents

Safety incidents (delivery, equipment)

Regulatory violations

Fraud and financial crimes

 

Reporting Procedures

 

Internal Reporting:

 

All compliance incidents must be reported immediately to the Compliance team

Incident tracking and investigation procedures

Root cause analysis and corrective actions

 

External Reporting:

 

Data Breaches: Notification to SDAIA within 72 hours; notification to affected individuals without undue delay

Cybersecurity Incidents: Notification to NCA as required

Safety Incidents: Notification to SERA and relevant authorities

Financial Crimes: Reporting to SAMA and law enforcement

 

Incident Documentation

 

All incidents are thoroughly documented, including:

 

Incident details and timeline

Investigation findings

Remediation actions taken

Lessons learned and preventive measures

 

4. Supplier and Third-Party Compliance

4.1 Supplier Verification Process

All energy suppliers on our platform undergo rigorous verification, including:

 

Business License Verification: Valid commercial registration and energy distribution licenses

Safety Certifications: SASO certifications for vehicles and equipment

Insurance Verification: Adequate liability and vehicle insurance

Background Checks: Verification of company and key personnel

Financial Due Diligence: Assessment of financial stability

Compliance History: Review of regulatory compliance record

 

4.2 Ongoing Supplier Monitoring

Performance Monitoring:

 

Delivery performance and customer satisfaction ratings

Safety incident tracking

Compliance with platform policies and standards

 

Periodic Re-verification:

 

Annual renewal of licenses and certifications

Periodic audits of high-volume suppliers

Compliance attestations

 

Supplier Training:

 

Onboarding training on platform policies and procedures

Safety and compliance training

Updates on regulatory changes

 

4.3 Third-Party Service Provider Management

Due Diligence:

 

All third-party service providers (payment processors, cloud providers, analytics tools) undergo due diligence assessments covering:

 

Data protection and security practices

Regulatory compliance

Financial stability

Reputation and track record

 

Contractual Safeguards:

 

Data Processing Agreements (DPAs) with all processors

Service Level Agreements (SLAs) with performance metrics

Confidentiality and security obligations

Audit rights and compliance reporting requirements

Liability and indemnification provisions

 

Ongoing Oversight:

 

Regular review of third-party compliance reports and certifications

Periodic assessments and audits

Incident notification and response coordination

 

5. Data Protection and Privacy Compliance

5.1 PDPL Compliance Program

Data Mapping and Inventory

 

We maintain a comprehensive data inventory documenting:

 

Categories of personal data collected

Sources of personal data

Purposes of processing

Legal basis for processing

Data recipients and transfers

Retention periods

 

Privacy by Design and Default

 

We implement privacy considerations into all new systems, products, and services from the design stage, including:

 

Data minimization principles

Purpose limitation

Default privacy settings

Pseudonymization and anonymization where possible

 

Data Subject Rights Management

 

We have established processes to handle data subject requests efficiently:

 

Online portal for submitting requests

Verification procedures to confirm identity

Response within 30 days

Tracking and documentation of all requests

 

Cross-Border Transfer Compliance

 

For all transfers of personal data outside Saudi Arabia, we implement:

 

Standard Contractual Clauses (SCCs)

Transfer Risk Assessments (TRAs) for sensitive data

Data Processing Agreements with international processors

Documentation of transfer mechanisms

 

Data Breach Response

 

Our data breach response plan includes:

 

Immediate containment and investigation

Assessment of risk to data subjects

Notification to SDAIA within 72 hours

Notification to affected individuals (if high risk)

Documentation and post-incident review

 

5.2 Data Protection Officer (DPO)

Our DPO is responsible for:

 

Monitoring compliance with PDPL and other data protection laws

Advising on data protection impact assessments (DPIAs)

Serving as point of contact for SDAIA and data subjects

Conducting privacy training and awareness programs

Reporting to senior management on data protection matters

 

DPO Contact: [email protected]

 

6. Cybersecurity Compliance

6.1 Security Controls

We implement comprehensive security controls aligned with NCA Essential Cybersecurity Controls (ECC) and ISO 27001:

 

Access Controls:

 

Role-based access control (RBAC)

Multi-factor authentication (MFA) for all user accounts

Privileged access management (PAM)

Regular access reviews and recertification

 

Network Security:

 

Firewalls and intrusion detection/prevention systems (IDS/IPS)

Network segmentation and isolation

Virtual private networks (VPNs) for remote access

DDoS protection

 

Data Security:

 

Encryption in transit (TLS 1.3)

Encryption at rest (AES-256)

Secure key management

Data loss prevention (DLP) tools

 

Application Security:

 

Secure software development lifecycle (SDLC)

Regular code reviews and security testing

Web application firewall (WAF)

API security controls

 

Endpoint Security:

 

Antivirus and anti-malware protection

Endpoint detection and response (EDR)

Mobile device management (MDM)

Patch management

 

Security Monitoring:

 

24/7 Security Operations Center (SOC)

Security Information and Event Management (SIEM)

Threat intelligence integration

Automated alerting and response

 

6.2 Vulnerability Management

Regular vulnerability scanning (weekly)

Annual penetration testing by independent third parties

Bug bounty program for responsible disclosure

Patch management with prioritization based on risk

Remediation tracking and verification

 

6.3 Incident Response

Our cybersecurity incident response plan includes:

 

Incident detection and triage

Containment and eradication

Recovery and restoration

Post-incident analysis and lessons learned

Notification to NCA and other authorities as required

 

7. Financial Compliance

7.1 Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF)

Risk-Based Approach:

 

We apply a risk-based approach to AML/CTF compliance, with enhanced due diligence for higher-risk customers and transactions.

 

Know Your Customer (KYC):

 

Identity verification for all corporate clients and suppliers

Beneficial ownership identification

Ongoing monitoring and periodic re-verification

 

Transaction Monitoring:

 

Automated monitoring for suspicious transaction patterns

Threshold-based alerts for large transactions

Investigation and documentation of suspicious activities

 

Suspicious Activity Reporting:

 

Procedures for identifying and reporting suspicious activities to SAMA and relevant authorities

Confidentiality and non-tipping-off obligations

 

Staff Training:

 

Regular AML/CTF training for all relevant staff

Updates on emerging risks and typologies

 

7.2 Payment Card Industry Data Security Standard (PCI-DSS)

We are PCI-DSS compliant through our partnership with certified payment processors. We do not store, process, or transmit payment card data directly, minimizing PCI scope.

 

Compliance Measures:

 

Use of PCI-DSS certified payment gateways

Secure tokenization of payment information

Regular security assessments

Quarterly network scans by Approved Scanning Vendors (ASVs)

 

8. Certifications and Standards

ENTEK.AI maintains the following certifications and adheres to international standards:

 

9. Reporting and Transparency

9.1 Regulatory Reporting

We submit regular reports to regulatory authorities, including:

 

SDAIA: Annual data protection compliance reports

SERA: Quarterly operational and safety reports

SAMA: AML/CTF compliance reports

NCA: Cybersecurity incident reports

GAZT: Monthly VAT returns and annual tax filings

 

9.2 Transparency Reports

We publish annual transparency reports disclosing:

 

Data subject requests received and processed

Data breaches and incidents

Government requests for data

Compliance certifications and audit results

 

9.3 ESG Reporting

We publish annual ESG reports covering:

 

Carbon emissions data and reduction initiatives

Social impact metrics (jobs created, community programs)

Governance practices and compliance performance

Progress toward Saudi Vision 2030 goals

 

10. Continuous Improvement

ENTEK.AI is committed to continuous improvement of our compliance program through:

 

Regular review and update of policies and procedures

Benchmarking against industry best practices

Incorporation of lessons learned from incidents and audits

Investment in compliance technology and automation

Engagement with regulators, industry associations, and stakeholders

Monitoring of regulatory developments and emerging risks

 

11. Contact Information

For compliance-related inquiries, please contact:

 

Chief Compliance Officer

Email: [email protected]

Phone: 920005469

 

Data Protection Officer

Email: [email protected]

 

General Compliance Inquiries

Email: [email protected]

 

Whistleblower Hotline (Anonymous Reporting)

Email: [email protected]

Phone: [Hotline Number]

 

12. Regulatory Authority Contact Information

 

 

Acknowledgment: This Compliance Documentation represents ENTEK.AI's commitment to operating with the highest standards of legal, regulatory, and ethical compliance. We continuously monitor and adapt our compliance program to meet evolving regulatory requirements and industry best practices.

 

Document Version: 1.0

Next Review Date: November 12, 2026