Security Overview
How GateKeeper protects your site and your users.
Security-First Design
GateKeeper is built with security at every layer. We combine advanced bot detection, cryptographic challenges, and multi-layered verification to protect your site -- while keeping your data safe and under your control.
Our Approach
GateKeeper uses a multi-layered approach to bot detection that goes far beyond traditional CAPTCHAs. Our system analyzes behavioral patterns, environmental signals, and timing characteristics to distinguish real users from automated threats -- including the latest generation of AI agents.
Every verification request passes through cryptographic proof-of-work challenges that make automated attacks computationally expensive, while remaining seamless for legitimate users. Our adaptive difficulty system continuously adjusts challenge complexity based on real-time threat assessment.
Behavioral signals are collected from your browser and scored on our servers to distinguish humans from automated threats. These signals are retained in pseudonymized form -- with IP addresses cryptographically hashed -- for up to 12 months to detect and continually improve defenses against bots, under a legitimate-interest basis (security and fraud prevention) recognized by the Saudi Personal Data Protection Law (PDPL). No tracking cookies or cross-site profiles are created.
Data Protection
We apply industry-standard encryption for all data at rest and in transit. Passwords are protected using modern, secure hashing algorithms. Our systems undergo regular security assessments to identify and address potential vulnerabilities.
Encryption
Industry-standard encryption at rest and in transit for all customer data and system communications.
Privacy by Design
No tracking cookies, no cross-site profiling. Behavioral signals are scored on our servers and retained in pseudonymized form (with IP addresses hashed) for up to 12 months for bot detection and the continual improvement of our defenses, then automatically deleted.
Data Residency
All GateKeeper infrastructure is hosted in Riyadh, Saudi Arabia. Your data never leaves the Kingdom. This ensures full compliance with Saudi data residency requirements and the Personal Data Protection Law (PDPL).
- All data processing and storage occurs within Saudi Arabia
- Virtual Cloud Network with private subnets and least-privilege access
- Web Application Firewall for DDoS protection
- No public network access to data stores
Compliance
| Standard | Status |
|---|---|
| PDPL (Saudi Personal Data Protection Law) | Compliant |
| WCAG 2.2 AA (Accessibility) | Compliant |
| SAMA Cyber Security Framework | Aligned |
| NCA Essential Cybersecurity Controls | Aligned |
Data Retention
We retain data only as long as necessary for its intended purpose. Audit logs are retained for 365 days. Behavioral verification signals are collected and scored server-side, then retained in pseudonymized form (with IP addresses cryptographically hashed) for up to 12 months to detect bots and improve our detection models, after which they are automatically deleted. Full details on our data retention periods and lawful basis are available in our Privacy Policy.
Incident Response
We maintain a structured incident response process to detect, contain, and resolve security incidents swiftly.
- Detection: Continuous automated monitoring and alerting for anomalous activity.
- Containment: Rapid isolation of affected systems to prevent further impact.
- Investigation: Root cause analysis to determine scope and origin of the incident.
- Remediation: Fix vulnerabilities and restore normal service operations.
- Notification: Affected users are informed within 72 hours, in compliance with PDPL requirements.
- Post-Incident Review: Lessons learned are documented and procedures are updated.
Vulnerability Reporting
If you discover a security vulnerability, we encourage responsible disclosure. Please report it to our security team so we can address it promptly.
Security Team: security@gatekeeper.sa
Please include detailed steps to reproduce the vulnerability. We respond to all reports within 48 hours and will work with you to resolve the issue.
Contact
For security-related inquiries:
Security Team: security@gatekeeper.sa
General Inquiries: support@gatekeeper.sa
Location: Riyadh, Saudi Arabia