regulation10.ae

Trust and evidence

Proof, not promises

Everything on this page is verifiable. We list what we can substantiate today, and we date the facts we cite. We do not publish customer names, testimonials, metrics, or analyst placements that we do not hold.

Exec X AI Ltd operates this service under DIFC commercial licence 10474. You can search that licence on the DIFC public register. Khaled Shivji, Autonomous Systems Officer, writes what appears here and signs it

This is a new company and it has no published references. So nothing on this page asks you to take our word for anything. Each item below names a source, a date, or a mechanism you can check yourself

Registered DIFC entity

Exec X AI Ltd operates the platform under DIFC commercial licence number 10474. The entity is listed on the DIFC public register, which anyone can search to confirm the licence.

Verify: DIFC Public Register, licence 10474 (as of 2026-08-30)

Built to DIFC Regulation 10

regulation10.ae implements Regulation 10 of the DIFC Data Protection Regulations (enacted 1 September 2023) together with the DIFC Data Protection Law No. 5 of 2020: it registers each AI system, runs the checks, and keeps the proof the Commissioner can require. The controls mapping is maintained in the product and available for review under NDA.

Verify: DIFC Data Protection Regulations, Regulation 10 (enacted 1 September 2023); DIFC Data Protection Law No. 5 of 2020 (as of 2026-08-30)

ISO/IEC 42001 crosswalk (readiness, not certification)

The platform's AI management-system controls are mapped to ISO/IEC 42001:2023. This is a documented crosswalk and internal readiness assessment; it is not a certification, and no certification is claimed. The crosswalk is available for review under NDA.

Verify: ISO/IEC 42001:2023 (AI management systems) (as of 2026-08-30)

Tamper-evident, evidence-grade audit trail

Every regulated action is written to a hash-chained audit log with per-tenant chain heads and independently stored, signed checkpoints, so a later edit or truncation is detectable. The public assessment sandbox already produces an evidence register with a SHA-256 proof-of-record for each artefact it generates.

Verify: In-platform: audit-room evidence register and audit checkpoints (as of 2026-08-30)

How we stop our own claims drifting

Every external claim we make is registered with the surfaces it appears on and a probe that reads the running code. A probe that cannot establish a claim returns unknown, never true. A claim a probe refutes comes off the site. The registry is printed in full further down this page, with the verdict each probe returned on this request

Verify: On this page: the claims registry, generated from the registry module (as of 2026-08-30)

Governed AI, transparently disclosed

Every AI model call the platform makes runs through a guarded provider with guardrails, a canary check, and tenant-attributed audit rows. Each registered system gets a plain-language transparency notice generated by the deterministic engines. The AI-governance policy is published to customers.

Verify: In-platform: policy coverage, transparency notices, guarded model provider (as of 2026-08-30)

Customer references

We do not have published, named customer references yet. When a customer agrees to be named, their case study will appear here with their own consent. Until then we will not invent one, and we will not present a pilot or a pseudonymous logo as a reference.

If you would like to speak with the team about a reference call or a proof of concept, start with an assessment and we will follow up.

Residency, sub-processors and security

These are the answers to the three questions every buyer asks first. Each value is resolved from this deployments own configuration and from the published legal register, so what you read here is what this service actually does.

Data residency

Tenant data is resident at rest in the Azure UAE North region. Classify and redact inference runs on an Azure OpenAI deployment in Azure Sweden Central, on the Data Zone Standard deployment type, processed within Microsoft's EU data zone, which is on the DIFC adequacy list. Judgement and explain inference runs on a deployment provisioned in UAE North on the Global Standard deployment type, which Microsoft documents as capable of being processed in any Azure region. We therefore commit to where data is stored at rest and to where each inference deployment is provisioned, and we make no claim that inference is executed in country.

Tenant data at rest
UAE North
Azure region identifier
uaenorth
Transfer safeguard
DIFC standard contractual clauses (Article 27)
Transfer regime
Articles 26 and 27 of the DIFC DPL

Verify: Residency and international transfers

Sub-processors

Every sub-processor below is bound by a written agreement no less protective than our data processing addendum (Article 24 of the DIFC DPL). The register is a disclosure of actual data flows: a vendor we do not send data to is not listed, and a new flow is published before it starts. Object to a change at privacy@regulation10.ae.

Microsoft Azure
Hosting, compute, Cosmos DB, WORM blob storage, AI inference (Azure OpenAI), and the self-hosted site analytics we run ourselves
Stripe
Subscription billing and payment processing
Resend
Transactional and notification email delivery
Vercel
Marketing-site hosting and CDN

Transactional email on this deployment is delivered through Azure Communication Services Email, which falls under the Microsoft Azure entry above and adds no further third party.

Verify: The full sub-processor register

Security

We apply technical and organisational measures appropriate to the risk under Article 14 of the DIFC DPL: encryption in transit and at rest, role-based access control, multi-factor authentication, and a sealed, tamper-evident audit trail.

Security duty
Article 14 of the DIFC DPL
Breach notification
We notify you of a personal-data breach without undue delay and support your notification duties to the DIFC Commissioner of Data Protection under Article 41 of the DIFC DPL.
Tenant data residency
UAE North
Certification
None claimed. The ISO/IEC 42001 mapping above is a documented crosswalk and internal readiness assessment, not a certification.

Verify: Security and your rights in the privacy policy

How we stop our own claims drifting

This page checked 25 claims when you loaded it. 6 came back true, 3 came back false, and 16 came back unknown. Every external claim we make is registered with the surfaces it appears on and a probe that reads the running code

A probe that cannot establish a claim returns unknown, never true. Some probes read a verification artefact in the repository, and this service does not install that reader. Those claims report unknown to you, which is the rule working rather than failing

This is what stops our marketing drifting away from our code. When a probe turns a claim false, the sentence comes off the site rather than being softened

true
The probe found the capability present
false
The probe found it absent. The sentence must not appear on any surface while this holds
unknown
The probe could not establish it. Unverified is never upgraded to true
  • Residency data at rest uae north

    True

    Claim: Customer evidence and artefacts are held at rest in the UAE, in Microsoft Azure UAE North.

    Probe: Environment posture. The probe reads the configuration that selects this deployment's posture. It proves the configuration, not the fact

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md §6.1, apps/marketing/app/(marketing)/security/page.tsx, apps/web/lib/support-kb-content.ts

  • Residency inference may leave region

    True

    Claim: Model inference may be processed in any Azure region, so no claim of in-country inference is made on the .ae service.

    Probe: Behavioural. The probe calls the real code and watches what it does

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md §6.2, apps/marketing/app/(marketing)/security/page.tsx, apps/marketing/app/(marketing)/legal/subprocessors/page.tsx

  • Residency secondary copy sweden central

    Unknown

    Statement under probe, not currently published: A secondary copy of tenant evidence is held in Sweden Central for resilience.

    Probe: Environment posture. The probe reads the configuration that selects this deployment's posture. It proves the configuration, not the fact

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md (withdrawn from §1.6, §6.1 and diagram D5)

  • Worm storage policy locked

    False

    Statement under probe, not currently published: Sealed records cannot be altered or deleted by anyone, including us.

    Probe: Behavioural. The probe calls the real code and watches what it does

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md §6.3, apps/marketing/app/(marketing)/legal/dpa/page.tsx, apps/marketing/lib/glossary.ts, apps/web/app/audit-room

  • Sealed tamper evident

    True

    Claim: Artefacts are sealed and tamper-evident: create-only writes that reject overwrite, a SHA-256 hash recorded on the document and printed in its footer, and an append-only hash-chained ledger.

    Probe: Behavioural. The probe calls the real code and watches what it does

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md §6.3, apps/marketing/app/(marketing)/transparency/page.tsx, apps/web/components/worm-retention-diagram.tsx

  • Artefact arabic

    False

    Statement under probe, not currently published: Regulation 10 artefacts are available in Arabic.

    Probe: Environment posture. The probe reads the configuration that selects this deployment's posture. It proves the configuration, not the fact

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md §6.4, apps/web/lib/support-kb-content.ts, apps/marketing/app/(marketing)/platform/page.tsx

  • Acb read only transfer

    Unknown

    Statement under probe, not currently published: A completed evidence set can be transmitted to an Accredited Certification Body without that body receiving any write access.

    Probe: Evidence seam. The probe checks that a named verification artefact exists in the repository. It proves the check was written, not that it passed

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md §1.7 and §6.5, apps/web/lib/support-kb-content.ts

  • No automatic submission

    Unknown

    Statement under probe, not currently published: The platform will not submit, file or transmit anything automatically; transmission requires an explicit user action.

    Probe: Evidence seam. The probe checks that a named verification artefact exists in the repository. It proves the check was written, not that it passed

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md §6.6, apps/marketing/app/(marketing)/platform/page.tsx, apps/web/lib/support-kb-content.ts

  • Export open formats

    Unknown

    Statement under probe, not currently published: Exports are produced in open, machine-readable formats and are independently verifiable by a third party.

    Probe: Evidence seam. The probe checks that a named verification artefact exists in the repository. It proves the check was written, not that it passed

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md §6.5 and §7, apps/marketing/app/(marketing)/platform/page.tsx

  • Entra auth live

    True

    Claim: Enterprise sign-in through Microsoft Entra is live on the production service.

    Probe: Behavioural. The probe calls the real code and watches what it does

    Surfaces: apps/marketing/app/(marketing)/security/page.tsx, apps/web/lib/support-kb-content.ts

  • Corpus primary sourced

    True

    Claim: Regulatory guidance is grounded in DIFC primary sources with traceable citations, and is versioned so downstream artefacts are flagged when the source changes.

    Probe: Behavioural. The probe calls the real code and watches what it does

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md §3, apps/marketing/app/(marketing)/transparency/page.tsx

  • Reg10 enacted 2023

    Unknown

    Statement under probe, not currently published: Regulation 10 of the DIFC Data Protection Regulations was enacted in September 2023 and has been in force since 1 September 2023.

    Probe: Evidence seam. The probe checks that a named verification artefact exists in the repository. It proves the check was written, not that it passed

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md §2, packages/corpus/src/difc.json

  • Self application

    False

    Statement under probe, not currently published: Exec X AI Ltd holds its own Regulation 10 evidence in the platform and can produce its own register entry and transparency notice on request.

    Probe: Environment posture. The probe reads the configuration that selects this deployment's posture. It proves the configuration, not the fact

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md §7

  • External facts verified

    Unknown

    Statement under probe, not currently published: The external regulatory facts asserted in the Commissioner brief (enforcement commencement, Schedule 2 fines, Regulation 11 status, the addressee) are verified against a primary source.

    Probe: Evidence seam. The probe checks that a named verification artefact exists in the repository. It proves the check was written, not that it passed

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md §2, §5, §8 and the cover block

  • Ledger tip witnessed

    Unknown

    Statement under probe, not currently published: The record is entered into an append-only hash-chained ledger, and the ledger tip is periodically signed and witnessed by a separate process.

    Probe: Evidence seam. The probe checks that a named verification artefact exists in the repository. It proves the check was written, not that it passed

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md §6.3

  • No edit or delete path

    Unknown

    Statement under probe, not currently published: The interface offers no path to edit, delete or backdate a sealed record.

    Probe: Evidence seam. The probe checks that a named verification artefact exists in the repository. It proves the check was written, not that it passed

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md §6.3, apps/web/app/audit-room

  • Human signoff before seal

    Unknown

    Statement under probe, not currently published: No artefact reaches a sealed state without a named human approving it.

    Probe: Evidence seam. The probe checks that a named verification artefact exists in the repository. It proves the check was written, not that it passed

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md §6.6

  • Runtime gateway enforcement

    Unknown

    Statement under probe, not currently published: The runtime gateway applies the firm's own policy to each call: allow, block, redact, or route to a human. Each decision is recorded.

    Probe: Evidence seam. The probe checks that a named verification artefact exists in the repository. It proves the check was written, not that it passed

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md §3

  • Model routing disclosed per call

    Unknown

    Statement under probe, not currently published: Model inference routing is disclosed to the customer, is recorded per call in the gateway decision record, and is configurable.

    Probe: Evidence seam. The probe checks that a named verification artefact exists in the repository. It proves the check was written, not that it passed

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md §6.2, docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md diagram briefs

  • Classification derived not asserted

    Unknown

    Statement under probe, not currently published: The classification is not asserted; it is derived, and the derivation shows which trigger fired and against which provision.

    Probe: Evidence seam. The probe checks that a named verification artefact exists in the repository. It proves the check was written, not that it passed

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md §3

  • Difc market statistics

    Unknown

    Statement under probe, not currently published: DIFC reported 10,018 active registered companies at the end of H1 2026, up 30 per cent year on year, with AI, FinTech and Innovation entities at 1,933, up 39 per cent.

    Probe: Evidence seam. The probe checks that a named verification artefact exists in the repository. It proves the check was written, not that it passed

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md executive summary point 2, §5 and Annex B

  • Invented reg10 duties

    Unknown

    Statement under probe, not currently published: Regulation 10 imposes no Commissioner-notification duty and no filing deadline for a Substantial Change; the register duty at 10.2.2(g) is to provide on request.

    Probe: Behavioural. The probe calls the real code and watches what it does

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md §2 and §4, apps/web/lib/public-copy.ts, apps/marketing/lib/glossary.ts, apps/marketing/content/knowledge/substantial-change.md

  • Human in the loop arabic

    True

    Claim: Arabic legal artefacts are produced with a human in the loop: an AI drafting aid, then mandatory sign-off from a named legal reviewer before any Arabic artefact is issued, with provenance recorded.

    Probe: Behavioural. The probe calls the real code and watches what it does

    Surfaces: docs/regulator/DIFC-COMMISSIONER-BRIEF-DRAFT-v1.md §6.4, apps/web/lib/arabic-translation.ts

  • Claim registry published

    Unknown

    Statement under probe, not currently published: Every external claim we make is registered with the surfaces it appears on and a probe that reads the running code. A probe that cannot establish a claim returns unknown, never true.

    Probe: Evidence seam. The probe checks that a named verification artefact exists in the repository. It proves the check was written, not that it passed

    Surfaces: apps/web/app/trust/page.tsx, apps/web/components/trust/claims-registry.tsx, apps/web/lib/growth/evidence/trust-registry.ts, apps/web/app/page.tsx

  • Sentinel closed beta not enrollable

    Unknown

    Statement under probe, not currently published: Sentinel, real-time monitoring, is scoped to the Enterprise and Sovereign plans, is a closed beta, and is not open for enrolment. The platform side that receives and verifies signed telemetry is built; the sentinel that would run inside a customer's own cloud is not built, so no customer estate is monitored today.

    Probe: Evidence seam. The probe checks that a named verification artefact exists in the repository. It proves the check was written, not that it passed

    Surfaces: apps/web/app/sentinel/page.tsx, apps/web/app/demo/demo-panels.tsx, apps/web/lib/landing/home-sections.ts, apps/web/lib/landing/cloud-flow-model.ts, apps/web/lib/sentinel-flow-model.ts, apps/web/lib/seo/llms.ts, apps/web/lib/seo/json-ld.ts, apps/marketing/lib/llms.ts, apps/marketing/lib/json-ld.ts, apps/marketing/app/(marketing)/security/page.tsx, apps/marketing/app/(marketing)/platform/page.tsx

Get started

See the evidence-grade output for yourself

The public sandbox produces a real evidence register, with a SHA-256 proof-of-record for each artefact, from a system you describe. No signup, nothing stored.

Open the assessment sandbox