Thiqa

Own Credibility, Thiqa keeps it proven

The compliance agent that knows where you stand and acts on it — collecting the evidence, writing your policies, treating the risk. Across MENA licences and global frameworks.

Early access · work email only

EvidenceEV-041

Encryption at rest

AWS · APIAutomated

Cloud infrastructure · Cryptography · read directly, no manual step

12 of 12 databases encrypted

Collected 29 Aug 2026 · next 28 Sept

Every database Thiqa can see uses AES-256 with a customer-managed KMS key.

Discovered databasesDescribeDBInstances · 4 regions
  • prod-db-1eu-west-1Aurora PostgreSQLAES-256 · KMS
  • prod-db-2me-south-1RDS PostgreSQL 15.4AES-256 · KMS
  • prod-db-3eu-west-1RDS PostgreSQL 15.4AES-256 · KMS
  • prod-db-4me-south-1Aurora PostgreSQLAES-256 · KMS
  • prod-db-5eu-west-1RDS MySQL 8.0AES-256 · KMS
  • prod-db-6eu-central-1Aurora MySQLAES-256 · KMS

Currently covering

  • FRA
  • PDPL
  • SAMA
  • PCI DSS
  • ISO 27001
  • ISO 27701
  • SOC 2
  • GDPR
  • NIST CSF

The Compliance Agent that gets it done

Thiqa Agent, assess your licensing & framework requirments, collects evidence automatically, generates and edits policies, assess and treats risk and much more. Making GRC operations smooth, reliable & fast.

NEW REQUEST

Map it once

Thiqa ingests your spreadsheets and controls and computes your posture. Everything maps to one control set, so evidence collected once answers every framework that asks for it.

Connect your systems

Thiqa connects to your systems read-only. It reads your repositories, workspace and cloud to collect evidence automatically and surface where your compliance and risk gaps are. Data is masked in transit and encrypted at rest.

The agent does the work

The agent collects the evidence, checks it against the obligation it proves, drafts the policy that answers it, and proposes a treatment for what’s left. All under your approval settings.

Your team signs off

All AI actions are reviewed and approved by humans before reaching an auditor ensuring a reliable and stable continuous auditable compliance posture.

  1. 01. Map it once — Thiqa ingests your spreadsheets and controls and computes your posture. Everything maps to one control set, so evidence collected once answers every framework that asks for it.
  2. 02. Connect your systems — Thiqa connects to your systems read-only. It reads your repositories, workspace and cloud to collect evidence automatically and surface where your compliance and risk gaps are. Data is masked in transit and encrypted at rest.
  3. 03. The agent does the work — The agent collects the evidence, checks it against the obligation it proves, drafts the policy that answers it, and proposes a treatment for what’s left. All under your approval settings.
  4. 04. Your team signs off — All AI actions are reviewed and approved by humans before reaching an auditor ensuring a reliable and stable continuous auditable compliance posture.

We cover your entire compliance data

Radar

Compliance Posture

83%

74/89 controls compliant across active frameworks

Central Bank of Egypt

Inspect

100

PCI DSS

Inspect

100

ISO 27001

Inspect

63

AI ingestion

Add framework

Overview

Controls

89/89 controls fulfilled

100

Policies

89/89 policies published

100

Documents

54/86 documents up to date

63

Evidence Collected

54/86 documents up to date

63

Risk Exposure

Medium

1

2

3

4

5

6

7

8

9

10

Negligible

Low

Medium

High

Critical

Vendor Risk

Medium

1

2

3

4

5

6

7

8

9

10

Negligible

Low

Medium

High

Critical

Gaps

3 block

15

down 4 this week

Aug

now

Closed this week

4

Opened this week

1

Open the queue

Critical Actions

All

8

Evidence

4

Documents

2

Policies

2

Provide evidence for regulatory & breach reporting

A documented process shall identify and maintain all compliance-lapse, cybersecurity-incident and data-breach reporting duties, including responsible authorities and required timeline.

THQ-05

Governance

CBE · 1 ref

ISO 27001 · 1 ref

High

Provide evidence for asset inventory & ownership

A documented asset-management process shall identify and maintain an inventory of information and associated assets with owners, location, description and lifecycle status.

THQ-11

Risk & Asset Management

CBE · 1 ref

ISO 27001 · 1 ref

High

The highest data granularity in the market to actually get the job done.

Features

  • Compliance Radar
  • Gap Assessment
  • Compliance Posture Computation
  • Live Framework & License progress

Multiple Entities, Licenses & Framework coverage

Our modular approach allows you to combine or switch between entities, jurisdictions & frameworks and the whole product changes with you

Features

  • Multiple Legal Entity Structures
  • License Coverage
  • Multi-Framework configuration

Thiqa

Scope

Egypt ▾

Obligations

Controls

Evidence

Risk

Scope

Everything on every screen is filtered by this.

Entities

All entities

10

Egypt

3

United Arab Emirates

4

Saudi Arabia

2

European Union

3

Frameworks

3 selected

CBE Governance

Egypt

SAMA CSF

Saudi Arabia

DIFC DP Law

UAE

PCI DSS v4.0

all

ISO 27001:2022

all

GDPR

EU

SOC 2 Type II

all

Egypt · CBE Governance, PCI DSS, ISO 27001

Apply scope

Covering all your GRC needs to reach a reliable outcome

7 features that fully provide end-to-end automations and simplicity for all of your GRC needs.

Policies

The agent drafts every policy and maps each block to a requirement as it writes. You edit, it answers.

Policies

/

POL-004

Incident Management & Response

Thiqa is writing

Writing section 4 of 6 · Regulatory notification

Reading CBE Article 5 and the two controls that already exist.

SECTION 4.0

Editing

Regulatory notification

Applies to every incident classified severity 1 or 2 under section 3.0.

Where an incident affects customer funds, cardholder data or the availability of a payment service, [Group] shall notify the Central Bank of Egypt within 24 hours of confirming the incident.

Answers CBE Art 5

The notification shall state the time of confirmation, the systems affected, the containment steps taken and the named incident manager.

Answers CBE Art 5.1

Controls

Control state is derived from evidence. There is no status dropdown.

Controls

89/89 controls fulfilled

100

Policies

89/89 policies published

100

Documents

54/86 documents up to date

63

Evidence collected

54/86 evidence current

63

Evidence

The agent collects it, checks it against the obligation and files it.

Encryption at rest

AWS · APIAutomated

Cloud infrastructure · Cryptography

12 of 12 databases encrypted

Collected 29 Aug 2026 · next 28 Sept

Discovered databases

prod-db-1

eu-west-1

AES-256 · KMS

prod-db-2

me-south-1

AES-256 · KMS

prod-db-3

eu-west-1

AES-256 · KMS

prod-db-4

me-south-1

AES-256 · KMS

prod-db-5

eu-central-1

AES-256 · KMS

Documents

Collected automatically from where they already live, versioned and tied to the obligation they answer.

Documents

Auto-collected

DOC-001: Company details

GRC · Governance · synced 2 min ago

Collected

DOC-003: Locations in scope

GRC · Scoping · synced 2 min ago

Collected

DOC-006: PCI Req 3.4 PAN access list

IT · Access control · collecting…

Collecting

Risk

Likelihood × impact, with AI-drafted treatments. Residual risk is derived, never guessed.

Likelihood

5

4

3

2

1

Insignificant

Minor

Moderate

Major

Severe

Inherent

After treatment

Vendors

Vendor assurance from onboarding to review.

Vendor Risk

Medium

1

2

3

4

5

6

7

8

9

10

Negligible

Medium

Critical

Frameworks

Every framework you answer to, mapped once.

ISO/IEC 27001:2022

Active

Information security management · 121 controls

Overview

Controls121Updates4

Readiness

34 of 121 controls met

28% complete

Connect with your existing stack

Integrates with the tools you already use to automatically collect evidence and keep you compliant.

Compliance for every stage of growth

You’ve just been licensed, and compliance is suddenly your problem. Thiqa reads what your licence actually asks of you, then goes and collects the proof from the tools you already run. Startup compliance, handled before you’re ready to hire for it.

Early access

Questions we get asked

CBE and FRA in Egypt, SAMA in Saudi Arabia, and CBUAE, DIFC and ADGM in the UAE — alongside PCI DSS v4.0, ISO 27001, SOC 2 and GDPR. Obligations are scoped per licensed entity, so each entity answers to the regulators it actually holds a licence with.

Don’t buy another tool. Get the real outcome.